RE: IBM/MSFT whitepaper on secure, reliable, transacted Web se rv ices
"Abbie Barbir" <[email protected]> Tue, 30 Sep 2003 09:55:04 -0400
| Newsgroups | gmane.comp.web.services.description,gmane.comp.web.services.ws-arch |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C3875A.72D86DBE Content-Type: text/plain Anne, very good, Thanks I may also add that assertions are only used once. Abbie > -----Original Message----- > From: Anne Thomas Manes [mailto:[email protected]] > Sent: Tuesday, September 30, 2003 9:50 AM > To: Champion, Mike; Cutler, Roger (RogerCutler); Sanjiva > Weerawarana; [email protected]; [email protected] > Subject: RE: IBM/MSFT whitepaper on secure, reliable, > transacted Web serv ices > > > > Mike's right. SAML and WS-* are very complementary. But let > me give you a > little more detail. > > SAML supports general-purpose security. It is not focused only on Web > services or SOAP. SAML defines three core capabilities: > 1- how to represent security tokens in XML. These tokens are called > assertions, and SAML defines three types of assertions -- > authentication, > authorization, and attributes. (attributes provide qualifying > information > that constrain the other assertions -- such as spending > limits or timing > contraints). An assertion is made by some type of trust > authority. So for > example, it says that the ChevronTexaco single sign-on > service asserts that > Roger Cutler passed a userid/password challenge at 9:00 AM on > 9/30/03, and > this assertion is good for 2 hours. > 2- a process model for obtaining security tokens from a trust > authority. > This includes a set of protocols for accessing a trust > authority. SAML > defines two types of trust authorities: Policy Decision > Points (PDPs) and > Policy Enforcement Points (PEPs). SAML has defined bindings > for multiple > protocols, including SOAP/WSDL. > 3- a set of protocol bindings for conveying SAML tokens. SAML > 1.1 defines > how to pass SAML tokens for browser applications. It does not define > bindings for how to pass SAML tokens in SOAP messages -- it > left that task > to the WS-Security team. > > WS-Security and the related specs focus on securing SOAP messaging. > WS-Security defines two core capabilities: > 1- how to use XML-Signature and XML-Encryption with SOAP > messaging. It > specifies how to pass signatures and key information in a SOAP header. > 2- how to pass security tokens with a SOAP message. > WS-Security supports a > variety of security tokens (each defined by its own binding > specification), > such as userid/password, X.509 certificates, Kerberos > tickets, and SAML tokens. > > Regards, > Anne > > At 06:54 PM 9/29/2003 -0400, Champion, Mike wrote: > > > > > > > > -----Original Message----- > > > From: Cutler, Roger (RogerCutler) > > > [mailto:[email protected]] > > > Sent: Monday, September 29, 2003 5:39 PM > > > To: Sanjiva Weerawarana; [email protected]; [email protected] > > > Subject: RE: IBM/MSFT whitepaper on secure, reliable, > transacted Web > > > services > > > > > > > > > I know that this is a dumb question, but could you > explain how the > > > WS-* specs relate to SAML? Is the SAML functionality in WS-* > > > somewhere, so that the specs are incompatible? Or does > WS-* operate > > > in a different space and interact with SAML somehow? > > > >As best I understand it, WS-Security provides a framework for > >exchanging / negotiating security-related information, and > SAML would > >describe one particular type of payload for WS-Security > messages, i.e. > >those that make assertions about identity, authentication, > >authorization, etc. They are definitely complementary, not > >competitive: WS-Security talks about SOAP headers and provides a > >generic security processing model; SAML doesn't know anything about > >SOAP but knows a lot more about the details of security semantics. > > > ------_=_NextPart_001_01C3875A.72D86DBE Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"> <META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2656.31"> <TITLE>RE: IBM/MSFT whitepaper on secure, reliable, transacted Web serv ices</TITLE> </HEAD> <BODY> <BR> <P><FONT SIZE=2>Anne,</FONT> </P> <P><FONT SIZE=2>very good, Thanks</FONT> </P> <P><FONT SIZE=2>I may also add that assertions are only used once.</FONT> </P> <P><FONT SIZE=2>Abbie</FONT> </P> <P><FONT SIZE=2>> -----Original Message-----</FONT> <BR><FONT SIZE=2>> From: Anne Thomas Manes [<A HREF="mailto:[email protected]">mailto:[email protected]</A>] </FONT> <BR><FONT SIZE=2>> Sent: Tuesday, September 30, 2003 9:50 AM</FONT> <BR><FONT SIZE=2>> To: Champion, Mike; Cutler, Roger (RogerCutler); Sanjiva </FONT> <BR><FONT SIZE=2>> Weerawarana; [email protected]; [email protected]</FONT> <BR><FONT SIZE=2>> Subject: RE: IBM/MSFT whitepaper on secure, reliable, </FONT> <BR><FONT SIZE=2>> transacted Web serv ices</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> Mike's right. SAML and WS-* are very complementary. But let </FONT> <BR><FONT SIZE=2>> me give you a </FONT> <BR><FONT SIZE=2>> little more detail.</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> SAML supports general-purpose security. It is not focused only on Web </FONT> <BR><FONT SIZE=2>> services or SOAP. SAML defines three core capabilities:</FONT> <BR><FONT SIZE=2>> 1- how to represent security tokens in XML. These tokens are called </FONT> <BR><FONT SIZE=2>> assertions, and SAML defines three types of assertions -- </FONT> <BR><FONT SIZE=2>> authentication, </FONT> <BR><FONT SIZE=2>> authorization, and attributes. (attributes provide qualifying </FONT> <BR><FONT SIZE=2>> information </FONT> <BR><FONT SIZE=2>> that constrain the other assertions -- such as spending </FONT> <BR><FONT SIZE=2>> limits or timing </FONT> <BR><FONT SIZE=2>> contraints). An assertion is made by some type of trust </FONT> <BR><FONT SIZE=2>> authority. So for </FONT> <BR><FONT SIZE=2>> example, it says that the ChevronTexaco single sign-on </FONT> <BR><FONT SIZE=2>> service asserts that </FONT> <BR><FONT SIZE=2>> Roger Cutler passed a userid/password challenge at 9:00 AM on </FONT> <BR><FONT SIZE=2>> 9/30/03, and </FONT> <BR><FONT SIZE=2>> this assertion is good for 2 hours.</FONT> <BR><FONT SIZE=2>> 2- a process model for obtaining security tokens from a trust </FONT> <BR><FONT SIZE=2>> authority. </FONT> <BR><FONT SIZE=2>> This includes a set of protocols for accessing a trust </FONT> <BR><FONT SIZE=2>> authority. SAML </FONT> <BR><FONT SIZE=2>> defines two types of trust authorities: Policy Decision </FONT> <BR><FONT SIZE=2>> Points (PDPs) and </FONT> <BR><FONT SIZE=2>> Policy Enforcement Points (PEPs). SAML has defined bindings </FONT> <BR><FONT SIZE=2>> for multiple </FONT> <BR><FONT SIZE=2>> protocols, including SOAP/WSDL.</FONT> <BR><FONT SIZE=2>> 3- a set of protocol bindings for conveying SAML tokens. SAML </FONT> <BR><FONT SIZE=2>> 1.1 defines </FONT> <BR><FONT SIZE=2>> how to pass SAML tokens for browser applications. It does not define </FONT> <BR><FONT SIZE=2>> bindings for how to pass SAML tokens in SOAP messages -- it </FONT> <BR><FONT SIZE=2>> left that task </FONT> <BR><FONT SIZE=2>> to the WS-Security team.</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> WS-Security and the related specs focus on securing SOAP messaging. </FONT> <BR><FONT SIZE=2>> WS-Security defines two core capabilities:</FONT> <BR><FONT SIZE=2>> 1- how to use XML-Signature and XML-Encryption with SOAP </FONT> <BR><FONT SIZE=2>> messaging. It </FONT> <BR><FONT SIZE=2>> specifies how to pass signatures and key information in a SOAP header.</FONT> <BR><FONT SIZE=2>> 2- how to pass security tokens with a SOAP message. </FONT> <BR><FONT SIZE=2>> WS-Security supports a </FONT> <BR><FONT SIZE=2>> variety of security tokens (each defined by its own binding </FONT> <BR><FONT SIZE=2>> specification), </FONT> <BR><FONT SIZE=2>> such as userid/password, X.509 certificates, Kerberos </FONT> <BR><FONT SIZE=2>> tickets, and SAML tokens.</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> Regards,</FONT> <BR><FONT SIZE=2>> Anne</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> At 06:54 PM 9/29/2003 -0400, Champion, Mike wrote:</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> ></FONT> <BR><FONT SIZE=2>> ></FONT> <BR><FONT SIZE=2>> > > -----Original Message-----</FONT> <BR><FONT SIZE=2>> > > From: Cutler, Roger (RogerCutler) </FONT> <BR><FONT SIZE=2>> > > [<A HREF="mailto:[email protected]">mailto:[email protected]</A>]</FONT> <BR><FONT SIZE=2>> > > Sent: Monday, September 29, 2003 5:39 PM</FONT> <BR><FONT SIZE=2>> > > To: Sanjiva Weerawarana; [email protected]; [email protected]</FONT> <BR><FONT SIZE=2>> > > Subject: RE: IBM/MSFT whitepaper on secure, reliable, </FONT> <BR><FONT SIZE=2>> transacted Web </FONT> <BR><FONT SIZE=2>> > > services</FONT> <BR><FONT SIZE=2>> > ></FONT> <BR><FONT SIZE=2>> > ></FONT> <BR><FONT SIZE=2>> > > I know that this is a dumb question, but could you </FONT> <BR><FONT SIZE=2>> explain how the </FONT> <BR><FONT SIZE=2>> > > WS-* specs relate to SAML? Is the SAML functionality in WS-* </FONT> <BR><FONT SIZE=2>> > > somewhere, so that the specs are incompatible? Or does </FONT> <BR><FONT SIZE=2>> WS-* operate </FONT> <BR><FONT SIZE=2>> > > in a different space and interact with SAML somehow?</FONT> <BR><FONT SIZE=2>> ></FONT> <BR><FONT SIZE=2>> >As best I understand it, WS-Security provides a framework for </FONT> <BR><FONT SIZE=2>> >exchanging / negotiating security-related information, and </FONT> <BR><FONT SIZE=2>> SAML would </FONT> <BR><FONT SIZE=2>> >describe one particular type of payload for WS-Security </FONT> <BR><FONT SIZE=2>> messages, i.e. </FONT> <BR><FONT SIZE=2>> >those that make assertions about identity, authentication, </FONT> <BR><FONT SIZE=2>> >authorization, etc. They are definitely complementary, not </FONT> <BR><FONT SIZE=2>> >competitive: WS-Security talks about SOAP headers and provides a </FONT> <BR><FONT SIZE=2>> >generic security processing model; SAML doesn't know anything about </FONT> <BR><FONT SIZE=2>> >SOAP but knows a lot more about the details of security semantics.</FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> </FONT> <BR><FONT SIZE=2>> </FONT> </P> </BODY> </HTML> ------_=_NextPart_001_01C3875A.72D86DBE--