Commentary

Alice LaPlante
 

SSO: The Holy Grail Of SOA

SAML (Security Assertion Markup Language) was in the spotlight again last week. An XML-based framework developed by OASIS Security Services Technical Committee, SAML allows companies to securely and automatically share identity information on the Web.

SAML (Security Assertion Markup Language) was in the spotlight again last week. An XML-based framework developed by OASIS Security Services Technical Committee, SAML allows companies to securely and automatically share identity information on the Web.First, Computer Associates announced its plans to use SAML 2.0 with eTrust SiteMinder, its Web access management product. The access management support eliminates the need to re-authenticate at each site; the product will thus allow customers to federate as identity providers or as service providers with multiple partners.

This announcement is an example of some general good news that is the focus of a special feature we have on federated identity management by Penny Lunt Crosman: that SAML 2.0 is entering the mainstream. But despite the gathering momentum, issues of trust and procedure must still be resolved, especially in this environment of frequent identity theft.


More Software Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

As Penny points out, Single Sign-On (SSO) has long been a holy grail for the IT community. But it has been a very distant grail for some time -- indeed, the analyst firm the Burton Group has switched to the term "reduced sign-on" because single sign-on sounds too nirvana-like.

Yet the reasons to strive for SSO are overwhelming. For productivity reasons, enterprises would love to give their employees access to all the applications they use during the day from a single login. This would also do away with all the help desk calls about forgotten passwords.

Externally, SSO would enable enormous efficiency gains. For example, a supply chain portal would be able let companies order supplies and check their suppliers' inventories or vice versa from one central place, or companies can give insurance or mortgage brokers simple online access to sell all their products.

SAML 2.0 is important because it represents the coming together of two important SSO standards efforts. After all, as recently as this past winter, various groups were working on competing standards, including SAML 1.x, the Liberty Alliance's ID-FF, Internet2's Shibboleth, and Microsoft's Passport. The Liberty Alliance and Internet2 chose to provide input to the latest version of SAML and help consolidate the standards into SAML 2.0. Read on, and learn for yourself why this is a highly significant standards release.

This week, we also featured an announcement from the Apache Foundation that it has launched what it calls its Synapse initiative, an open-source effort that seeks to produce a common, standardized way to broker services on a network. This is a significant announcement because if the initiative actually produces viable open-source code, it has the potential to challenge several commercial products, such as IBM's WebSphereMQ, Tibco Software's Rendezvous, and webMethods' Fabric. Check it out.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links