OASIS Open Mailing List Archives  ·  All Lists  ·  xspa-interop-tech  ·  2010-01

xspa-interop-tech — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Demonstrating WS-Trust


Hi all, My understanding of the previous XSPA interop events is that it has been mostly XACML-focused, with a VA-provided application calling out to the various vendor's PDPs to render an authorization decision. Will we be following a similar model for the demonstration of WS-Trust? Referring to Figure 1 of the XSPA WS-Trust profile (p. 8) The scenario I envisage is that the "Service User" will call out to various vendors' WS-Trust endpoints to obtain a SAML assertion used to call the "Service Provider". The implication of this is that the interop will have a pre-defined set of user accounts and associated XSPA attributes that each vendor should use to populate the contents of the SAML assertion. Does this sound right, or am I way off the mark? Also, will there be vendor-provided WS-Trust interactions on the Service Provider side in which the received SAML assertion is validated and potentially authorized? Regards, Craig --- craig forster | staff software engineer | ibm australia development labs

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]