← Prev in month ← Prev in thread

Demonstrating WS-Trust

From
Craig Forster
Date
2010-01-15T06:54:00+00:00
ID
Thread
Demonstrating WS-Trust
Hi all,

My understanding of the previous XSPA interop events is that it has been
mostly XACML-focused, with a VA-provided application calling out to the
various vendor's PDPs to render an authorization decision.

Will we be following a similar model for the demonstration of WS-Trust?
Referring to Figure 1 of the XSPA WS-Trust profile (p. 8) The scenario I
envisage is that the "Service User" will call out to various vendors'
WS-Trust endpoints to obtain a SAML assertion used to call the "Service
Provider".  The implication of this is that the interop will have a
pre-defined set of user accounts and associated XSPA attributes that each
vendor should use to populate the contents of the SAML assertion.

Does this sound right, or am I way off the mark?

Also, will there be vendor-provided WS-Trust interactions on the Service
Provider side in which the received SAML assertion is validated and
potentially authorized?

Regards,
Craig

---
craig forster | staff software engineer | ibm australia development labs
← Prev in month ← Prev in thread