|
Comments
Did you read today's front page stories & breaking news?
SYS-CON.TV
|
XML News Desk OASIS Members Ratify SAML as Open Standard, Enables Single Sign-On for Web Services
OASIS Members Ratify SAML as Open Standard, Enables Single Sign-On for Web Services
By: XML News Desk
Jan. 1, 2000 12:00 AM
(November 7, 2002) -- The members of the OASIS interoperability consortium have approved the Security Assertion Markup Language (SAML) v1.0 as an OASIS Open Standard, a status that signifies the highest level of ratification. Although Gartner analysts forecast rapid adoption of SAML, they also caution that enterprises implementing Web services will still face serious security challenges. SAML is an XML-based framework for Web services that allows the exchange of authentication and authorization information among business partners. SAML enables Web-based security interoperability functions, such as single sign-on, across sites hosted by multiple companies. "Most Web services vendors have announced plans to support SAML in the near future, and this widespread acceptance will simplify security integration across heterogeneous Web services environments, say Gartner analysts Ray Wagner and John Pescatore. But security challenges will persist, according to Gartner, particularly in managing the public and private keys required to implement signing and encryption. "SAML and the other leading Web services security initiatives all assume that keys or digital certificates and the infrastructure to manage them are readily available. This is not yet the case for most enterprises," they comment. Garter's recommendation: Enterprises should demand that vendors' Web services offerings support XKMS public-key management capabilities as well as SAML, XML encryption and signing, and, when available, WS-Security. "SAML 1.0 is an important industry standard for federating diverse security domains across Web services environments," said James Kobielus, senior analyst at Burton Group. "SAML 1.0 supports secure interchange of authentication and authorization information by leveraging the core Web services standards of Extensible Markup Language (XML), Simple Object Access Protocol (SOAP), and Transport Layer Security (TLS). Most vendors of Web access management solutions have committed to SAML 1.0 and are currently implementing the specification in their products." "SAML lets companies implement single sign-on solutions that allow users to visit various Web sites without being repeatedly challenged for credentials," explained Joe Pato of HP, co-chair of the OASIS Security Services Technical Committee. "In addition, SAML makes it possible to include security information in documents used in business transactions. This is particularly relevant for Web services, where security is critical." SAML incorporates industry-standard protocols and messaging frameworks, such as XML Signature, XML Encryption, and SOAP. The specification can be easily integrated in standard environments such as HTTP and standard Web browsers. Other security environments can use SAML as an authentication and authorization layer. SAML complements Web services standards, such as SOAP, which lack inherent security features. "SAML allows vendors to interoperate for the benefit of their customers," said Jeff Hodges, Sun Microsystems, co-chair of the OASIS Security Services Technical Committee. "The standard is easily implemented by companies in existing environments, and SAML-aware security applications are already being introduced. Related security initiatives, such as Liberty Alliance's Version One Specification, are leveraging SAML in order to more quickly realize their goals." The SAML OASIS Open Standard was developed by Baltimore Technologies, BEA Systems, Computer Associates, Entrust, Hewlett-Packard Company, Hitachi, IBM, Netegrity, Oblix, OpenNetwork, Quadrasis, RSA Security, Sun Microsystems, Verisign, and other members of the OASIS Security Services Technical Committee. Reader Feedback: Page 1 of 1
SOA World Latest Stories
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
|
SYS-CON Featured Whitepapers
Most Read This Week |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||