Web service clients can be implemented as JavaServer Pages, servlets, or Java applications, or as executables written in C++, Perl, Visual Basic, JavaScript. A truly ubiquitous protocol. In this article, I use a Java application as a Web service client and show how to secure that client from an authentication and authorization standpoint via Role-based Access Control (RBAC). Basically, role-based authorization is achieved by using:
The SAML XML.org web site is not longer accepting new posts. Information on this page is preserved for legacy purposes only. For current information on SAML, please see the OASIS Security Services Technical Committee Wiki.
News
News lets the community share announcements, press releases, and recommended news articles relevant to SAML. (Educational materials that are not time-sensitive are listed at Articles and white papers.)
SAML, JAAS, & Role-Based Access Control
Agencies to link in $25m australia.gov.au revamp
Finance Minister Lindsey Tanner yesterday announced that EDS had won an AU$25 million contract over four years to create australia.gov.au, a "one-stop-shop" for all government information and services. Users will be able to create an account and personalise the site so they can easily access information or services from different government agencies. The portal will also be able to pre-populate forms with details from their profile, and allow users to complete the forms offline. The authentication hub is based on the Security Assertion Markup Language (SAML) 2.0 standard.
IBM Pushes Federated Identity Management
IBM is pushing interoperability as a solution to enterprise identity management and authentication woes. In Version 6.2 of IBM Tivoli Federated Identity Manager, the company has integrated a number of user-focused identity management technologies and frameworks, including OpenID, Microsoft Windows CardSpace and the Eclipse Higgins identity framework.
Fedlet
Fedlet is a lightweight Service Provider implementation of SAML2 SSO
protocols, embeddable in a Java EE web application. Fedlet is a new
feature, which will be part of upcoming Sun Federated Access Manager
(OpenSSO) release.
Liberty Alliance Announces Judging Panel for the 2008 IDDY Awards
NEW YORK, May 22 /PRNewswire/ -- Liberty Alliance, the global identity community working to build a more trust-worthy internet for consumers, governments and businesses worldwide, today announced the judging panel for the 2008 IDDY (IDentity Deployment of the Year) Awards. This year judges will be evaluating nominations in three categories: a Liberty-based deployment, a Liberty-based emerging application and a new multi-protocol application category. The call for nominations for the 2008 IDDY Awards ends on Monday, June 16, with winners announced on June 30.