* Sun, Microsoft allow single sign-on to Liberty Alliance, WS-* Web services
Last week’s Digital ID World conference in San Francisco was, as I mentioned in the last issue, a “Kim Cameron Love-in.” But there was some heat generated in at least one area – federation services.
The rivalry between the Microsoft-led Web Services Initiative (WS-*) and the Sun-led Liberty Alliance was ever present with digs and barbs coming at almost every session where federation was even remotely related to the topic. It all came to a head during a heated panel discussion moderated by Burton Group Associate Research Director, the mild-mannered Mike Neuenschwander (who seemed more bemused than worried by the antics of his panelists and their audience). Most of us walked away from the conference on Thursday convinced that convergence of the two standards was farther away then ever.
So it was with a great deal of surprise to many of us when Sun’s Scott McNealy and Microsoft’s Steve Ballmer took the stage together (without a referee) last Friday at a press conference in Palo Alto, to announce that yes, indeed, progress was being made on the convergence front.
It’s rare for McNealy to speak on identity issues and unprecedented for Ballmer. It’s also very rare for either to say nice things about the other’s company.
And let me hasten to say they haven’t buried the hatchet, joined hands and decided to teach the world to sing “Kumbaya” (https://www.peterpaulandmary.com/music/20-13.htm). But they have agreed to start the journey towards a convergence of standards by announcing that the two companies have developed a set of specifications that enable Web single sign-on (SSO) between systems that use Liberty and WS-* Web service architectures. This isn’t a major piece of the identity puzzle by any means, it’s more important symbolically. And symbolically, it’s a very big step. I can imagine that a number of major customers of both organizations sat them down and said, “Stop the posturing and start solving my problems.”
As McNeally said: “A year ago, the skeptics doubted that we could agree on the shape of the table, much less collaborate on solving some of the industry’s toughest problems. Surprise – we did just that!”
The companies have jointly developed and published two draft specifications: Web Single Sign-On Metadata Exchange (Web SSO MEX) Protocol and Web Single Sign-On Interoperability Profile (Web SSO Interop Profile). These new specifications will enable browser-based Web SSO between security domains that use Liberty ID-FF (https://www.projectliberty.org/specs/liberty-idff-arch-overview-v1.2.pdf) and WS-Federation (https://www-106.ibm.com/developerworks/webservices/library/ws-fed/).
The new specs are available from both Microsoft (https://msdn.microsoft.com/webservices/understanding/specs/default.aspx?pull=/library/en-us/dnglobspec/html/wssecurspecindex.asp) and Sun (https://developers.sun.com/techtopics/identity/interop/index.html)
What a difference a day makes!




