Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft details Windows 8 for ARM devices
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
/

Plan on SAML for identity mgmt.

Related linksToday's breaking news
Send to a friendFeedback



The Security Assertion Markup Language interoperability bake-off and release of an eagerly awaited specification from the Liberty Alliance last month mark historic steps forward for Web services, security and distributed applications.

An XML-based standard, SAML provides a means for applications or security servers to exchange portable identity assertions that authenticate or authorize users.

The Liberty Alliance Version 1.0 specification builds on SAML, enabling identity domains keeping local accounts or profiles for the same user to link those records on an opt-in basis.

Together, SAML and the Liberty specification are great tools to expand your identity management options. A traveler could make car, hotel and airline reservations from a single site while taking advantage of frequent flyer, renter and guest "loyalty accounts" held at multiple companies. A doctor could federate from a hospital IT system to a third-party imaging company's X-ray database with roles-based access control.

As the excitement of SAML/Liberty's debut fades, however, sober reflection must begin. The standards will provide great tools, but companies need to understand how and where to use them. And there's still much work to be done.

First and foremost, additional common-denominator standards, legal or commercial frameworks, and best practices for federated identity will be needed. Today, you can hope to work with partners across peer-to-peer, hub-and-spoke or small circles-of-trust arrangements. But just as it was difficult at first to interconnect regional ATM networks into a global financial system, multiple challenges will limit universal, multiparty use of SAML/Liberty.

Among these challenges are competitive disincentives for sharing data between businesses, practical difficulties with Web security and lack of scalable public-key infrastructure (PKI) trust models.

Early adopters will face familiar and unfamiliar pitfalls, but these will be manageable. Allow some time for growing pains with early products supporting the standards. Federation can't occur in an identity vacuum, so you'll have to continue the sometimes painful process of building authoritative directories in-house. However, federation tools provide a possible solution for linking existing directories. Looking forward, lawyers and business owners must create the privacy policies and trading-partner agreements underpinning trust relationships. But establishing agreements and trusts for SAML/Liberty can be significantly easier than designing a full-blown PKI or other alternatives.

The challenges are many, but they are unlikely to stop the SAML/Liberty train. Federated identity can bring real business benefits. Look for federation opportunities across the Internet, among business units, or even between disparate IT systems. Factor SAML/Liberty into your identity management architecture.

RELATED LINKS

Blum is a senior vice president and principal consultant with The Burton Group, an IT advisory service providing in-depth analysis for network planners. He can be reached at

dblum@tbg.com.

More Intranet Advisor columns

Liberty Alliance spec

Error 404--Not Found

Error 404--Not Found

From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:

10.4.5 404 Not Found

The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.

If the server does not wish to make this information available to the client, the status code 403 (Forbidden) can be used instead. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.