OASIS Open Mailing List Archives  ·  All Lists  ·  xspa-interop-tech  ·  2010-01

xspa-interop-tech — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Minutes RSA 2010 Interop Technical Call - January 19th, 2010




  


We also need to have a standard way to inject the attributes from the
client at run time.

We may use Claims again, as a child of RST, but with a different Dialect and syntax, e.g.
Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context

The element may like this:
<t:Claims Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context" xmlns:xspa="http://schemas.xmlsoap.org/ws/xspa/claims">
                                <xspa:ClaimType Uri="urn:oasis:names:tc:xspa:1.0:subject:purposeofuese">
                                                    <xspa:Value>Emergency Treatment</xspa:Value>
                                                    <xspa:Value>Healthcare Treatment</xspa:Value>
                               </xspa:ClaimType>
</t:Claims>

WS-Federation also defines an element
auth:AdditionalContext

as a child of RSA that can be used for this purpose. But I am not the support for this is mature enough to use it.

Thanks!

Jiandong



Jiandong Guo wrote:
[email protected]" type="cite"> Duane DeCouteau wrote:
[email protected]" type="cite">

Action Items

Daniel - Provide most recent copy of HIMSS 2009 XACML policy
Duane - post policy to WIKI.
Duane - Publish on WIKI the attributes required in request from client (XSPA Requestor), and those requested from PIP
Jiandong - will update XSPAInterop wsdls WS-Policy with those required attributes
Attached is a sample wsdl with policy. Here the protection token is the service x509 certificate.
There are two endorsing tokens (the ones supplied by the client) IssuedToken (from STS) and an X509 certificate (
I changed from SupportingToekn to EndorsingSupportingToken to make sure it is passed it passed in a secured way).

For IssuedToken I add a sample Claims to indicate to client what the attributes required to access the service. I made
up some url to illusttrate.

Thanks!

Jiandong


[email protected]" type="cite">Duane - To define and publish on WIKI where opportunities from WS-Trust vendors to plug-in services into existing applications
Duane/Emory Fry - Discuss plans for exposing testbed from KMR Arizona development site.


--------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php


[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]