RE: IBM/MSFT whitepaper on secure, reliable, transacted Web se rv ices

"Abbie Barbir" <[email protected]> Tue, 30 Sep 2003 09:55:04 -0400
Newsgroups gmane.comp.web.services.description,gmane.comp.web.services.ws-arch
Message-ID <[email protected]>
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C3875A.72D86DBE
Content-Type: text/plain


Anne,

very good, Thanks

I may also add that assertions are only used once.

Abbie

> -----Original Message-----
> From: Anne Thomas Manes [mailto:[email protected]] 
> Sent: Tuesday, September 30, 2003 9:50 AM
> To: Champion, Mike; Cutler, Roger (RogerCutler); Sanjiva 
> Weerawarana; [email protected]; [email protected]
> Subject: RE: IBM/MSFT whitepaper on secure, reliable, 
> transacted Web serv ices
> 
> 
> 
> Mike's right. SAML and WS-* are very complementary. But let 
> me give you a 
> little more detail.
> 
> SAML supports general-purpose security. It is not focused only on Web 
> services or SOAP. SAML defines three core capabilities:
> 1- how to represent security tokens in XML. These tokens are called 
> assertions, and SAML defines three types of assertions -- 
> authentication, 
> authorization, and attributes. (attributes provide qualifying 
> information 
> that constrain the other assertions -- such as spending 
> limits or timing 
> contraints). An assertion is made by some type of trust 
> authority. So for 
> example, it says that the ChevronTexaco single sign-on 
> service asserts that 
> Roger Cutler passed a userid/password challenge at 9:00 AM on 
> 9/30/03, and 
> this assertion is good for 2 hours.
> 2- a process model for obtaining security tokens from a trust 
> authority. 
> This includes a set of protocols for accessing a trust 
> authority. SAML 
> defines two types of trust authorities: Policy Decision 
> Points (PDPs) and 
> Policy Enforcement Points (PEPs). SAML has defined bindings 
> for multiple 
> protocols, including SOAP/WSDL.
> 3- a set of protocol bindings for conveying SAML tokens. SAML 
> 1.1 defines 
> how to pass SAML tokens for browser applications. It does not define 
> bindings for how to pass SAML tokens in SOAP messages -- it 
> left that task 
> to the WS-Security team.
> 
> WS-Security and the related specs focus on securing SOAP messaging. 
> WS-Security defines two core capabilities:
> 1- how to use XML-Signature and XML-Encryption with SOAP 
> messaging. It 
> specifies how to pass signatures and key information in a SOAP header.
> 2- how to pass security tokens with a SOAP message. 
> WS-Security supports a 
> variety of security tokens (each defined by its own binding 
> specification), 
> such as userid/password, X.509 certificates, Kerberos 
> tickets, and SAML tokens.
> 
> Regards,
> Anne
> 
> At 06:54 PM 9/29/2003 -0400, Champion, Mike wrote:
> 
> >
> >
> > > -----Original Message-----
> > > From: Cutler, Roger (RogerCutler) 
> > > [mailto:[email protected]]
> > > Sent: Monday, September 29, 2003 5:39 PM
> > > To: Sanjiva Weerawarana; [email protected]; [email protected]
> > > Subject: RE: IBM/MSFT whitepaper on secure, reliable, 
> transacted Web 
> > > services
> > >
> > >
> > > I know that this is a dumb question, but could you 
> explain how the 
> > > WS-* specs relate to SAML?  Is the SAML functionality in WS-* 
> > > somewhere, so that the specs are incompatible?  Or does 
> WS-* operate 
> > > in a different space and interact with SAML somehow?
> >
> >As best I understand it, WS-Security provides a framework for 
> >exchanging / negotiating security-related information, and 
> SAML would 
> >describe one particular type of payload for WS-Security 
> messages, i.e. 
> >those that make assertions about identity, authentication, 
> >authorization, etc.  They are definitely complementary, not 
> >competitive: WS-Security talks about SOAP headers and provides a 
> >generic security processing model; SAML doesn't know anything about 
> >SOAP but knows a lot more about the details of security semantics.
> 
> 
> 

------_=_NextPart_001_01C3875A.72D86DBE
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2656.31">
<TITLE>RE: IBM/MSFT whitepaper on secure, reliable, transacted Web    serv 	ices</TITLE>
</HEAD>
<BODY>
<BR>

<P><FONT SIZE=2>Anne,</FONT>
</P>

<P><FONT SIZE=2>very good, Thanks</FONT>
</P>

<P><FONT SIZE=2>I may also add that assertions are only used once.</FONT>
</P>

<P><FONT SIZE=2>Abbie</FONT>
</P>

<P><FONT SIZE=2>&gt; -----Original Message-----</FONT>
<BR><FONT SIZE=2>&gt; From: Anne Thomas Manes [<A HREF="mailto:[email protected]">mailto:[email protected]</A>] </FONT>
<BR><FONT SIZE=2>&gt; Sent: Tuesday, September 30, 2003 9:50 AM</FONT>
<BR><FONT SIZE=2>&gt; To: Champion, Mike; Cutler, Roger (RogerCutler); Sanjiva </FONT>
<BR><FONT SIZE=2>&gt; Weerawarana; [email protected]; [email protected]</FONT>
<BR><FONT SIZE=2>&gt; Subject: RE: IBM/MSFT whitepaper on secure, reliable, </FONT>
<BR><FONT SIZE=2>&gt; transacted Web serv ices</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; Mike's right. SAML and WS-* are very complementary. But let </FONT>
<BR><FONT SIZE=2>&gt; me give you a </FONT>
<BR><FONT SIZE=2>&gt; little more detail.</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; SAML supports general-purpose security. It is not focused only on Web </FONT>
<BR><FONT SIZE=2>&gt; services or SOAP. SAML defines three core capabilities:</FONT>
<BR><FONT SIZE=2>&gt; 1- how to represent security tokens in XML. These tokens are called </FONT>
<BR><FONT SIZE=2>&gt; assertions, and SAML defines three types of assertions -- </FONT>
<BR><FONT SIZE=2>&gt; authentication, </FONT>
<BR><FONT SIZE=2>&gt; authorization, and attributes. (attributes provide qualifying </FONT>
<BR><FONT SIZE=2>&gt; information </FONT>
<BR><FONT SIZE=2>&gt; that constrain the other assertions -- such as spending </FONT>
<BR><FONT SIZE=2>&gt; limits or timing </FONT>
<BR><FONT SIZE=2>&gt; contraints). An assertion is made by some type of trust </FONT>
<BR><FONT SIZE=2>&gt; authority. So for </FONT>
<BR><FONT SIZE=2>&gt; example, it says that the ChevronTexaco single sign-on </FONT>
<BR><FONT SIZE=2>&gt; service asserts that </FONT>
<BR><FONT SIZE=2>&gt; Roger Cutler passed a userid/password challenge at 9:00 AM on </FONT>
<BR><FONT SIZE=2>&gt; 9/30/03, and </FONT>
<BR><FONT SIZE=2>&gt; this assertion is good for 2 hours.</FONT>
<BR><FONT SIZE=2>&gt; 2- a process model for obtaining security tokens from a trust </FONT>
<BR><FONT SIZE=2>&gt; authority. </FONT>
<BR><FONT SIZE=2>&gt; This includes a set of protocols for accessing a trust </FONT>
<BR><FONT SIZE=2>&gt; authority. SAML </FONT>
<BR><FONT SIZE=2>&gt; defines two types of trust authorities: Policy Decision </FONT>
<BR><FONT SIZE=2>&gt; Points (PDPs) and </FONT>
<BR><FONT SIZE=2>&gt; Policy Enforcement Points (PEPs). SAML has defined bindings </FONT>
<BR><FONT SIZE=2>&gt; for multiple </FONT>
<BR><FONT SIZE=2>&gt; protocols, including SOAP/WSDL.</FONT>
<BR><FONT SIZE=2>&gt; 3- a set of protocol bindings for conveying SAML tokens. SAML </FONT>
<BR><FONT SIZE=2>&gt; 1.1 defines </FONT>
<BR><FONT SIZE=2>&gt; how to pass SAML tokens for browser applications. It does not define </FONT>
<BR><FONT SIZE=2>&gt; bindings for how to pass SAML tokens in SOAP messages -- it </FONT>
<BR><FONT SIZE=2>&gt; left that task </FONT>
<BR><FONT SIZE=2>&gt; to the WS-Security team.</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; WS-Security and the related specs focus on securing SOAP messaging. </FONT>
<BR><FONT SIZE=2>&gt; WS-Security defines two core capabilities:</FONT>
<BR><FONT SIZE=2>&gt; 1- how to use XML-Signature and XML-Encryption with SOAP </FONT>
<BR><FONT SIZE=2>&gt; messaging. It </FONT>
<BR><FONT SIZE=2>&gt; specifies how to pass signatures and key information in a SOAP header.</FONT>
<BR><FONT SIZE=2>&gt; 2- how to pass security tokens with a SOAP message. </FONT>
<BR><FONT SIZE=2>&gt; WS-Security supports a </FONT>
<BR><FONT SIZE=2>&gt; variety of security tokens (each defined by its own binding </FONT>
<BR><FONT SIZE=2>&gt; specification), </FONT>
<BR><FONT SIZE=2>&gt; such as userid/password, X.509 certificates, Kerberos </FONT>
<BR><FONT SIZE=2>&gt; tickets, and SAML tokens.</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; Regards,</FONT>
<BR><FONT SIZE=2>&gt; Anne</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; At 06:54 PM 9/29/2003 -0400, Champion, Mike wrote:</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; &gt;</FONT>
<BR><FONT SIZE=2>&gt; &gt;</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; -----Original Message-----</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; From: Cutler, Roger (RogerCutler) </FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; [<A HREF="mailto:[email protected]">mailto:[email protected]</A>]</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; Sent: Monday, September 29, 2003 5:39 PM</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; To: Sanjiva Weerawarana; [email protected]; [email protected]</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; Subject: RE: IBM/MSFT whitepaper on secure, reliable, </FONT>
<BR><FONT SIZE=2>&gt; transacted Web </FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; services</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt;</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt;</FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; I know that this is a dumb question, but could you </FONT>
<BR><FONT SIZE=2>&gt; explain how the </FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; WS-* specs relate to SAML?&nbsp; Is the SAML functionality in WS-* </FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; somewhere, so that the specs are incompatible?&nbsp; Or does </FONT>
<BR><FONT SIZE=2>&gt; WS-* operate </FONT>
<BR><FONT SIZE=2>&gt; &gt; &gt; in a different space and interact with SAML somehow?</FONT>
<BR><FONT SIZE=2>&gt; &gt;</FONT>
<BR><FONT SIZE=2>&gt; &gt;As best I understand it, WS-Security provides a framework for </FONT>
<BR><FONT SIZE=2>&gt; &gt;exchanging / negotiating security-related information, and </FONT>
<BR><FONT SIZE=2>&gt; SAML would </FONT>
<BR><FONT SIZE=2>&gt; &gt;describe one particular type of payload for WS-Security </FONT>
<BR><FONT SIZE=2>&gt; messages, i.e. </FONT>
<BR><FONT SIZE=2>&gt; &gt;those that make assertions about identity, authentication, </FONT>
<BR><FONT SIZE=2>&gt; &gt;authorization, etc.&nbsp; They are definitely complementary, not </FONT>
<BR><FONT SIZE=2>&gt; &gt;competitive: WS-Security talks about SOAP headers and provides a </FONT>
<BR><FONT SIZE=2>&gt; &gt;generic security processing model; SAML doesn't know anything about </FONT>
<BR><FONT SIZE=2>&gt; &gt;SOAP but knows a lot more about the details of security semantics.</FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; </FONT>
<BR><FONT SIZE=2>&gt; </FONT>
</P>

</BODY>
</HTML>
------_=_NextPart_001_01C3875A.72D86DBE--