« Thinking on Oauth, UMA and SPML | Main | OVD and OID 11g R1 PS1 now available on all platforms »

Follow-up on OAuth/UMA/SPML

Clark Sanford gave me some insightful comments on my OAuth/UMA/SPML/Federated Provisioning post.

In particular he's trying to promote the use of SAML Attribute Query as the way to provide callback in Federated Provisioning:
"
In the scenario Nishant describes where the original Assertion doesn't contain all the attributes/claims they want for provisioning, in a SAML implementation why couldn't the SP service initiate the Assertion Query profile to retrieve the desired additional attributes from the IdP service?
"
I think it's important to keep in mind the real competition isn't between SAML or OAuth or SPML. Rather the real competition is to convince people that they shouldn't be doing manual data entry (and storage) of person/identity data. That it is in fact queryable. That's the big hurdle.

Then the second hurdle is actually how to implement this. While SAML Attribute Query would seem to be a preferred choice (standard, most if not all federation products support it) - I think it's still too hard for the average developer to deploy a solution.

For example - he is something I would like to see details on:

How would a PHP developer write a SAML Attribute Query back to a SAML IDP that worked with any server that supported SAML 2?

Posted via email from Virtual Identity Dialogue

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About This Entry

This page contains a single entry from the blog posted on November 30, 2009 8:47 AM.

The previous post in this blog was Thinking on Oauth, UMA and SPML.

The next post in this blog is OVD and OID 11g R1 PS1 now available on all platforms.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type and Oracle