Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

January 2009
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Monthly Archives

Search The Blog

Eye on the Enterprise by Richard Adhikari (bio)

MIS Information



Call me SAML-Compliant

Well, okay, call me SAML 2.0 then, which isn't the same thing as SAML 1.0, an earlier version of the Security Assertion Markup Language.

SAML is the protocol used to achieve Single Sign-On between Web sites as well as authentication that enables safe transactions, among other things. As our Webopedia site explains, SAML defines mechanisms to exchange authentication, authorization and nonrepudiation information.

If all this identity standards alphabet soup drives people crazy, it's probably because some mighty fine hair splitting is often involved with which standard to use, since there are others like WS-Federation.

WS-Federation is also trying to address the identity and security requirements of both Web applications and Web services. Definitely not the same thing as SAML. But new projects have cropped up to make them act the same, such as Project Concordia, whose mission is to "drive interoperability across identity protocols in use today."

And overall, the industry is making progress with interoperability. The Liberty Alliance, for example, which includes IBM, Microsoft, Oracle and RSA, group just announced that "products from CA; NTT Software; Ping Identity; RSA, The Security Division of EMC; and Ubisecure have passed its Liberty Alliance SAML 2.0 interoperability testing."

It can get pretty mind-boggling.

So now that several vendors' products have passed its interoperability tests, what does this mean? Simple: If you log in and create an identity once for one of these vendors' applications, you will be able to access the other vendors' applications without having to go through the identity creation process again. It's the equivalent of logging in to your Yahoo mail and using the same login to access Gmail and your Amazon.com account on the Web.

No more remembering multiple passwords or the answers to security questions. It might even save vice-presidential candidates' e-mail accounts from being hacked.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Call me SAML-Compliant.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/5331

Leave a comment