Next in thread → Next in month →

RE: [provision] FW: Base SPML on SAML rather than DSML?

From
Gavenraj Sodhi <>
Date
2002-07-30T17:32:38+00:00
ID
A39D4CF11F759647B2CF46DE86917B9ACA1702@HQEXCH1
Thread
RE: [provision] FW: Base SPML on SAML rather than DSML?
I am 
also looking for a better perspective because I have raised the following in the 
past:

 

System 
A <-- SPML Identity Assertion -- SAML Assertion -- SPML Identity Assertion 
--> System B

 

What 
is included in the SPML Identity Assertion?  It may consist of some 
metadata from the SAML Authorization Decision Assertion but what else to 
acknowledge the request and response?  This goes back to Tony's last 
comment (before the question) below.

 

-Gavenraj

  
-----Original Message-----
From: Tony Gullotta 
  [mailto:]
Sent: Tuesday, July 30, 2002 10:09 
  AM
To: ''; Gavenraj Sodhi
Cc: 
  
Subject: RE: [provision] FW: Base 
  SPML on SAML rather than DSML?

  
I 
  think SAML may have some relevance if the PSP wishes to obtain additional 
  information about the principal who needs to be provisioned. So, for 
  example, let's say the provisioning request is for John Doe, and the 
  PSP needs to know John's credit status before authorizing the request. Then 
  the PSP could query the RA (or some trusted third party) for attribute 
  assertions about John's credit. This may make sense to be SAML based, however 
  the original provisioning request would probably not be a great fit. Does 
  anyone else have a better perspective on SAML to comment?

  
 

  
Tony

  
    
-----Original Message-----
From:  
    [mailto:]
Sent: Tuesday, July 30, 2002 8:32 
    AM
To: Gavenraj Sodhi
Cc: 
    
Subject: Re: [provision] FW: Base 
    SPML on SAML rather than DSML?

  SAML (so far) 
    doesn't have a protocol for updating attributes, just acquiring them (issue 
    an attribute request, get an attribute assertion back). You could devise a 
    protocol where a requestor instead submitted an attribute assertion (as a 
    request to update/add an attribute), but there is no support for that as a 
    protocol in SAML: is the assertion an add or an update, what should the 
    response of the receiver be, etc.

  Caveat: I haven't followed 
    the SAML list much for the past couple of 
    months.

Rob

Gavenraj Sodhi wrote: 
    

    fyi... 

-----Original Message----- 
From: 
      DeSouza, Edwin [mailto:] 
      
Sent: Monday, July 29, 2002 6:25 PM 
To: Gavenraj Sodhi; 
       
Cc: ; 
      ; 
; ; 
      ; 
 
Subject: Base SPML on SAML 
      rather than DSML? 

Darran, Gavenraj, 
I see a lot of 
      discussion on using DSML as the basis for SPML.  
http://lists.oasis-open.org/archives/provision/200207/maillist.html 
      

DSML is one possible starting point (Directories keep User 
      Profiles, etc 
--AND-- DSML is supposed to make directories talk to 
      each other). 

On the other hand, SAML is supposed to be able to 
      transport all kinds of 
"interesting" user profile info among various 
      
sites/companies/applications/etc.  And, given that Project 
      Liberty is 
using SAML, and maybe WS-Security will be friendly to SAML, 
      then in all 
likelihood SAML will have a much more widespead usage than 
      DSML. 

That being the case ... it would be interesting to think 
      about using 
SAML as the basis for SPML. 

Maybe someone more 
      technical/knowledgeable than me can start a 
discussion on this at 
      SPML. 

bye, 
Edwin. 
      

---------------------------------------------------------------- 
      
To subscribe or unsubscribe from this elist use the subscription 
      
manager: <http://lists.oasis-open.org/ob/adm.pl>
Next in thread → Next in month →