xspa-interop-tech — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Demonstrating WS-Trust
Hi all,
My understanding of the previous XSPA interop events is that it has been
mostly XACML-focused, with a VA-provided application calling out to the
various vendor's PDPs to render an authorization decision.
Will we be following a similar model for the demonstration of WS-Trust?
Referring to Figure 1 of the XSPA WS-Trust profile (p. 8) The scenario I
envisage is that the "Service User" will call out to various vendors'
WS-Trust endpoints to obtain a SAML assertion used to call the "Service
Provider". The implication of this is that the interop will have a
pre-defined set of user accounts and associated XSPA attributes that each
vendor should use to populate the contents of the SAML assertion.
Does this sound right, or am I way off the mark?
Also, will there be vendor-provided WS-Trust interactions on the Service
Provider side in which the received SAML assertion is validated and
potentially authorized?
Regards,
Craig
---
craig forster | staff software engineer | ibm australia development labs
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]