Clearly the next step is for Google to adopt Liberty Alliance ID-WSF to allow such partners to access Google applications in a non-browser context.
Tags:
When you don't have anything nice to say, well then perhaps its time consider a career as an analyst.
The study analyzes identity management and its crucial role in enabling personalized services. Identity management is viewed as a crucial element in a basket of technology enablers that will be instrumental in preventing network operators from experiencing a dreaded “bit pipe” fate.
Proposed, but not agreed, definitions for the different architectures are:
- User-Centric: user decides every time what identity attributes to reveal to the content provider
- Domain-Centric: user approves identity attributes appropriate to specific domains
- Federated: user approves transferring of identity attributes already given to other federation members
SAML and Liberty Alliance ID-WSF are in a marriage, and you can see why it's a strong one. The interactions that SAML covers (e.g. between IDP and SP) are those that ID-WSF doesn't and vice versa. The two are like those old couples who are able to successfully ignore each other and stay together forever (SAML's drinking is admittedly a problem but it is getting help).In a closed community in which a relying party only trusts the validation of credentials to be performed by a single identity provider, typically run by that same organization, then this is a non-issue. Other environments, such as in a federal government medium security infrastructure, a relying party may have an enumerated set of identity providers that it recognizes. In other environments, it is not clear how a relying party should choose the identity providers that it trusts.
Really great news coming on Ping Identity.
its still important to realize that SOAP-based systems of identity (SAML and WS-Federation) are still much more adept at maneuvering through high-risk transactions that take place onlineSAML does define a SOAP Binding as one mechanism for moving messages and assertions around. It also defines a number of other bindings that have nothing to do with SOAP.
<vrm:rfp>
<pol:all>
<vrm:item>
<air:flight return="1" maxConnect="1">
<air:from id="yow">YOW</air:from>
<air:to id="lhr">LHR</air:to>
<air:itin>
<air:day start="#yow" end="#lhr">07-07-07</air:day>
<air:day start="#lhr" end="#yow">14-07-07</air:day>
</air:itin>
</air:flight>
</vrm:item>
<vrm:item>
<air:flight return="1" maxConnect="2">
<air:from id="yow2">YOW</air:from>
<air:to id="wel">WEL</air:to>
<air:itin>
<air:day start="#yow2" end="#wel">10-09-07</air:day>
<air:day start="#wel" end="#yow2">24-09-07</air:day>
</air:itin>
</air:flight>
</vrm:item>
</pol:all>
</vrm:rfp>
Maybe, those Danish folk need to talk to us Americans and learn somethingWhat a novel phenomenon, an American who feels that the world simply needs to pay closer attention.
Q: Where is the Joe's location?
A: He's within 300 m of your store. I'll say no more.
<TestItem objectType="profile">
<TestOp>//Age >= ’18’</TestOp>
</TestItem>
tell computers who my friends areAmen to that.
I really, really want a single service where I can say “these people are my friends” and then when I sign up to any new website I can sync it with my previously-defined social network.This is exactly what the Liberty Alliance People Service is designed to provide. In the People Service model, registration at the new social application would go something like this
as far as I can tell is the only good way to move social graphs around that respect privacy.Thanks Kaliya, that was the goal so it's nice to hear. In my talk I will attempt to put the PS into context of other social mechanisms like FOAF and the microformat-based XFN, citing pros/cons of all.
Liberty 2.0R provides some excellent valueFinally, some recognition.
In response to your question “How can we help each other?”, the first step to me seems to be for the OpenID providers to allow people to sign into their OpenIDs with InfoCards, rather than username/password. Then OpenID users will automatically gain all the benefits of the CardSpace user experience ceremony.If Chuck Mortimer's proof-of-concept is OpenID within Cardspace, then this scenario (i.e. using Cardspace to authenticate to an OpenID IDP, at the behest of an OpenID RP, such that the OpenID IDP is a Cardspace RP) is OpenID followed by Cardspace - a weaker form of integration (and one of course possible with any other SSO system like SAML, as hilited by Ping).
he's in business class (middle column (2-3-2)) of a 3 class of service airplane... perhaps a 777
Curious if Liberty has decided to keep in (sic) simple strictly in the short-term or have decided to avoid tackling any of the issues surrounding the business scenarios and deferred it to the indefinite future..."Mildly obscene acronym starting with 'W' expressing complete bafflement"?



I am disappointed that Paul missed another approach mentioned in the document ( or may be I am missing something). Pat rightly identified the 2 typical models that can be implemented and Paul extended it by coming up with all the permutation and combinations using various components. But all the model discussed look to be various permutation of just one model i.e. Authorization Pull Model where the resource is resposible to connect to the Decision Point to get the result. I think a hybrid of the "Authorization Push Model" and Local policy evaluation is more appropriate for the federation model where along with the identity the authorization of subject itself will flow to the other domain.
It’s important to note that the above diagrams are intended to show configurations of components, not information flows. For instance, for any configuration that involves the sharing of subject attributes, these may be included in the actual request to access a resource, or they may be requested by the AEF (or other component) from the subject after receipt of the access request,
Hey Darlene, is one of them contestants named 'SAML', no wait, they must mean Samuel. Is there a 'Samuel' on the show?
No? well how 'bout a 'Uri'? Jeez, why are they putting one of those damn Russkis on the TV?
How nice, save me the effort of remembering my model by allowing me to provide the VIN and have them do the work. It's only been 5 hours and I'm already impressed by their customer service.We may use your vehicle VIN at some point in the future, for reasons as yet undetermined but nevertheless still governed by your acceptance of this policy.
Does Federated Identity sometimes require Federated Authorization? If so, how come this isn't ever discussed. Maybe you could address in future blog entry...As ever, Eve is special, she rated a slightly modified version.
Patients also need to be able to better coordinate and manage their own health information. We believe that patients should control and own their own health information, and should be able to do so easily. Today it is much too difficult to get access to one's health records, for example, because of the substantial administrative obstacles people have to go through and the many places they have to go to collect it all. Compare this to financial information, which is much more available from the various institutions that help manage your financial "health."Currently, Google has no credibility here. They could buy some though.
Normal caveats about over simplification, not drawn to scale, etc.My boss is aIs it true Dick drives a Pinto? and he's actually *A Prestige?
Canadian
from BC
specifically
Vancouver
where they'll hold the Olympics
in Gastown
who's male
42-years old
which means he's over 25
and under 65
who went to UBC
and is a CEO
and founder
and bartender
and belongs to the Vancouver Entrepreneur Forum
and is a blogger at blame.ca
who banks at HSBC
and flys Air Canada
and is a Star Alliance Gold member
who likes Macs
At Symlabs, we see our customers using AuthnContext for information about how a user was provisioned in the first place, and also how the user was authenticated for the current session.and
Symlabs was instrumental in getting the mobile authentication contexts defined, because our wireless operator customers requested our participation in this area.Indeed, I remember well the after-hours session (Paris?) with Sampo thrashing out the mobile classes for ID-FF.
I think this is perfectly appropriate as the ceremony he provides is exactly the same were the protocol OpenID and not SAML. Put another way, it's in the XRDS doc that the fact that the IDP speaks SAML and not OpenID is advertised, and not in the UI.
How did Sxip determine that my wife calls me "joesixpack"? Is appending 'et' designed to inhibit correlation?
They'll have to get into professional hockey the same way I did - through countless hours of practice, complete commitment, and learning how to sew those nice skirts. Lotto - Zo werkt Lotto Government Accredited Licensed lottery promoters. International Promotions/Prize Award Department.I replied with the following (from a suitably disposable address and after obfuscating above indices):
This Lottery is approved by the Netherlands Gaming Board and also Licensed by the The International Association of Gaming Regulators (IAG international emails. held on the 29th November, 2006.all winnings must be claim not later than Decembre 7th, 2006, after this date,unclaimed funds will be returned to the Lotto.
Your email won the lottery.For a total pay out of €1,000,000. no tickets were sold but all email addresses were assigned to different ticket numbers for representation and privacy.
Please remember to quote your reference number and batch numbers:
1, Batch 9484-9116-0076
2, Ref: 637405467-Nll
3, lucky numbers 1-0958-31-444
To file for your claim, please contact
**************************
Advocate Faber Dutchs
Tel: +31 -619 255 080
Fax: +31-84-728-9656
email- bejesbejes200@aim.com
From the desk of Renry HootLet's see if they are even set up to deal with responses.
Dear Sirs, thank you very much for the good news, I am ecstatic to hear about my good fortune. I have never won anybody before (Mrs. Hoot as the exception of course), much less 1 million Europeans!
Before we proceed I do have some questions on which I would appreciate clarification:
1) for those Europeans I have won, am I responsible for their travel costs from their respective homelands to mine? I do acknowledge that, even with this expense, I stand to benefit greatly from their subsequent labours, but I do need to budget accordingly.
2) To what standard of living are my prizes used? I do plan of course on providing them the base necessities but don't see the sense of spoiling them with luxuries beyond that to which they are accustomed. For instance, might a typical European find soap and similar toiletries an unexpected and unwelcome oddity? I'm sure you'll understand why I'd prefer to save this expense if possible.
3) Canada can be a cold country. Perhaps you could begin the conditioning process by occasional walk-in freezer sessions? If you could simultaneously broadcast French language programs to them that would be extremely helpful - it is that unique combination of shivering and strange vocalizations that typifies my country.
4) Related to above, any French language skills would be a welcome bonus (unless of course you are shipping me Frenchmen. If this is absolutely necessary please keep them to a minimum - Canada is already quite socialist enough Ha-Ha).
Thanks again. I'm very excited and happy to be the new owner of so many Europeans (although the task of choosing new names for them is daunting!)
Gratefully yours,
Renry Hoot
p.s. I wonder if your lottery might be affiliated with a similar one in Asia? Is there any precedent for trading some or all of my Europeans for Asians? I would be of course be willing to consider a considerable exchange rate, perhaps 5 to 1? Please advise if this is a possibility (and whether a donation to a 'charity' of your choice might expedite the process).
p = 7 (a small prime number)
p- 1 = 6
g = 2 (OpenID default)
X = g ^ x mod p
X = 2 ^ 5 mod 7
X = 32 mod 7
X = 4 (the remainder when you divide 7 into 35)
Y = g ^ y mod p
Y = 2 ^ 4 mod 7
Y = 16 mod 7
Y = 2 (the remainder when you divide 7 into 16)
RP calculates IDP calculates
s = Y ^ X mod p s' = X ^ Y mod p
s = 2 ^ 4 mod 7 s' = 4 ^ 2 mod 7
s = 16 mod 7 s' = 16 mod 7
s = 2 s' = 2
The conclusion?
Proprietary standardization seeks to increase a firm’s market share (pie sharing).
Open standardization seeks to increase the size of the market (pie expansion).
The results show that financial markets respond positively to announcements of proprietary XML schema standardization, but not to those of open XML schema standardization.How encouraging.
Most user already sign-in to different sites with the same password. Is 'safely' sufficient distinction?



I expect the shirt Pat wore accounts for his inflated ratings.
Who does this? Who is so insulated from dealing with their own spam that they are oblivious to the risk that giving away email addresses would mean for their friends or family?