Wednesday, May 02, 2007

Recently the WS-Federation 1.1 specification was submitted to OASIS with the intent to have it ratified. The spec is long and I have not yet had a chance to actually understand. But our experience at Safewhere with WS-Federation and WS-Trust is obviously a shared one; that is, you basically only need a passive profile whereas the active profile used for web services is already covered by WS-Trust. SOAP based federation may be viewed as simply chaining together Security Token Services as specified by WS-Trust and as such does not need its own seperate spec.

Don Schmidt of Microsoft has started to blog about some of these things and as one of the authors of the specs he should know.

posted on Wednesday, May 02, 2007 8:35:02 PM (Romance Daylight Time, UTC+02:00)  #    Comments [0]