Welcome to MSDN Blogs Sign in | Join | Help

Welcome to The Metaverse

Navigating the service-oriented, identity aware metaverse

News

  • Disclaimer:
    The content of this blog are my own personal opinions and do not necessarily represent Microsoft's position, commitments or strategy. In addition, my thoughts and opinions often change, and as a weblog is intended to provide a semi-permanent point in time snapshot you should not consider out of date posts to reflect my current thoughts and opinions.




    Add to Technorati Favorites
WS-Trust 1.3 and WS-SecureConversation 1.3 now standardized

There's a lot happening in the web-services standards world right now. A good example of this is that both WS-Trust 1.3 and WS-SecureConversation 1.3 have now been ratified by OASIS.

WS-Trust provides a simple protocol to allow someone to request a security token containing some set of claims from an Identity Provider (IdP). Because WS-Trust is part of the WS-* suite of protocols, it can be composed with other protocols to, for example, enjoy data integrity (signing) and data privacy (encryption) using WS-Security and WS-SecureConversation.

WS-SecureConversation adds to the capabilities of WS-Security and essentially enables the construction of a secure context that optimizes multiple calls between two parties.

These protocols are both used by Windows CardSpace, along with several other current and emerging technologies that enable dynamic, user-initiated identity federation.

Why is the ratification of these two important protocols a significant event? Well, as Gartner puts it:

"The availability of these new standards means that Web services security has finally reached an acceptable maturity level. The issuance and dissemination of credentials between different trust domains via an STS can now be achieved using a syntax that is familiar to most developers."

It's great to see the rich fabric of the WS-* protocols now reaching a level of maturity and sophistication that enable solutions to previously costly/difficult/impossible problems. Identity federation is just one example that many people don't even know they need, but once they start enjoying its benefits, will wonder how they did without it.

Posted: Friday, April 06, 2007 9:42 AM by richardt

Comments

Weblog di Fabio Cozzolino said:

Come segnala Richard Turner sul suo blogqualche giorno fa sono state standardizzate da OASIS le specifiche

# April 7, 2007 3:16 PM
Anonymous comments are disabled
Page view tracker