<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>des on Federated Identity ... less is more &#187; Information Cards</title>
	<atom:link href="http://identity-des.com/category/information-cards/feed/" rel="self" type="application/rss+xml" />
	<link>http://identity-des.com</link>
	<description>Thoughts on the reuse of digital identities through federation</description>
	<lastBuildDate>Thu, 19 May 2011 01:34:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Issuing Information Cards with AD FS 2.0</title>
		<link>http://identity-des.com/issuing-information-cards-with-ad-fs-2-0/</link>
		<comments>http://identity-des.com/issuing-information-cards-with-ad-fs-2-0/#comments</comments>
		<pubDate>Fri, 21 May 2010 18:22:01 +0000</pubDate>
		<dc:creator>Don Schmidt</dc:creator>
				<category><![CDATA[AD FS 2.0]]></category>
		<category><![CDATA[Federated Identity]]></category>
		<category><![CDATA[Information Cards]]></category>

		<guid isPermaLink="false">http://identity-des.com/?p=86</guid>
		<description><![CDATA[Today Microsoft introduced a Community Technical Preview (CTP) of an Information Card Issuance Add-on for Active Directory Federation Services 2.0 that was released earlier this month.  The CTP provides a software component for Administrators to install on an AD FS 2.0 server and configure it for issuing Information Cards.  These Cards can be used in conjunction with username/password, X.509 digital certificates, or Kerberos authentication for requesting security [...]]]></description>
			<content:encoded><![CDATA[<p>Today Microsoft introduced a Community Technical Preview <a href="http://blogs.technet.com/b/identity/archive/2010/05/24/availability-of-the-information-card-issuance-preview.aspx" target="_blank">(CTP) of an Information Card Issuance Add-on </a>for Active Directory Federation Services 2.0 that was <a href="http://identity-des.com/2010/05/20/ad-fs-2-0-a-saml-promise-delivered/" target="_blank">released</a> earlier this month.  The CTP provides a software component for Administrators to install on an AD FS 2.0 server and configure it for issuing Information Cards.  These Cards can be used in conjunction with username/password, X.509 digital certificates, or Kerberos authentication for requesting security tokens from an AD FS 2.0 server.</p>
<p>This CTP software will enable end users with IMI 1.0 or IMI 1.1 (draft) compliant identity selectors to obtain Information Cards from AD FS 2.0.  This includes the current CardSpace 2.0 beta, and CardSpace 1 which shipped with Windows 7 and Windows Vista and is available for download on Windows XP.  These Cards should work with other compatible identity selectors, both on Windows and on other platforms. </p>
<p>The goal of the CTP is to advance the community&#8217;s understanding of the requirements and benefits of Information Cards through testing, pilots and other non-production experiments.  Please ask questions and provide your feedback using the <a href="mailto:ici-ctp@microsoft.com">ici-ctp@microsoft.com</a> alias, or by participating in the Information Card Issuance <a href="http://social.msdn.microsoft.com/Forums/en-US/windowscardspace/threads">Forum</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://identity-des.com/issuing-information-cards-with-ad-fs-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft &#8220;Geneva&#8221; Server Supports SAML 2.0</title>
		<link>http://identity-des.com/microsoft-geneva-server-supports-saml-20/</link>
		<comments>http://identity-des.com/microsoft-geneva-server-supports-saml-20/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 10:29:31 +0000</pubDate>
		<dc:creator>Don Schmidt</dc:creator>
				<category><![CDATA[ADFS]]></category>
		<category><![CDATA[CardSpace]]></category>
		<category><![CDATA[Federated Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Web Services Standards]]></category>

		<guid isPermaLink="false">http://identity-des.com/?p=36</guid>
		<description><![CDATA[At the Professional Developers Conference this week Microsoft is announcing the beta release of &#8220;Geneva&#8221;, the codename for its new claims based access platform.  This platform helps developers and IT professionals simplify user access to applications and other systems with an open claims-based model.  “Geneva” helps developers to externalize user authentication and identity processing from application [...]]]></description>
			<content:encoded><![CDATA[<div><span style="font-size: small;"><span style="color: #000000; font-family: &quot;Lucida Sans Unicode&quot;,&quot;sans-serif&quot;;"></p>
<div><span style="font-size: 10pt; mso-bidi-font-size: 10.5pt;"></span></div>
<p></span></span></div>
<p><span style="font-size: small;"><span style="color: #000000; font-family: &quot;Lucida Sans Unicode&quot;,&quot;sans-serif&quot;;"><span style="font-size: 10pt; mso-bidi-font-size: 10.5pt;"><span style="font-family: Consolas;"></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 11.4pt;"><span style="font-size: 12pt; color: #000000; font-family: &quot;&quot;sans-serif&quot;&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"><span style="font-family: Calibri;">At the Professional Developers Conference this week Microsoft is announcing the beta release of </span><a href="http://www.networkworld.com/news/2008/102708-microsoft-identity-cloud.html"><span style="color: #0000ff;"><span style="font-family: Calibri;">&#8220;Geneva&#8221;</span></span></a><span style="font-family: Calibri;">, the codename for its new claims based access platform.<span style="mso-spacerun: yes;">  </span>This platform helps developers and IT professionals simplify user access to applications and other systems with an open claims-based model.<span style="mso-spacerun: yes;">  </span>“Geneva” helps developers to externalize user authentication and identity processing from application code by using claims that are obtained with pre-built security logic that is integrated with .NET tools.<span style="mso-spacerun: yes;">  </span>“Geneva” helps IT professionals to efficiently deploy and manage new applications by reducing user account management, promoting a consistent security model, and facilitating seamless collaboration across departmental, organizational and vendor boundaries.<span style="mso-spacerun: yes;">  </span>User access benefits include shortened provisioning lead times, reduced accounts, passwords and logins, and enhanced privacy support.<span style="mso-spacerun: yes;">  </span>“Geneva” implements the Identity Metasystem vision for open and interoperable identity, and includes built-in support for standard federated identity protocols.</span></span></p>
</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 11.4pt;"><span style="font-size: 12pt; color: #000000; font-family: &quot;&quot;sans-serif&quot;&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"><span style="font-family: Calibri;">A fundamental goal of “Geneva” is to extend the reach of its predecessor, Active Directory Federation Services, and provide a common identity programming model for developers of both web applications and web services.<span style="mso-spacerun: yes;">  </span>To maximize interoperability with clients and servers from other vendors, it supports the WS-Trust, WS-Federation and SAML 2.0 protocols.<span style="mso-spacerun: yes;">  </span>To maximize administrative efficiency “Geneva” automates federation trust configuration and management using the new </span><a href="http://identity-des.com/2008/10/28/harmonized-federation-metadata-for-ws-federation-and-saml/"><span style="color: #0000ff;"><span style="font-family: Calibri;">harmonized federation metadata format </span></span></a><span style="font-family: Calibri;">(based on SAML 2.0 metadata) that was recently adopted by the WSFED TC.</span></span></p>
</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-line-height-alt: 11.4pt;"><span style="font-family: Calibri;"><span style="font-size: 12pt; color: #000000; font-family: &quot;&quot;sans-serif&quot;&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';">WS-Trust is provided to support Information Card based Identity Selectors from third parties, as well as Windows CardSpace.  WS-Federation is required to maintain interoperability with existing federations being operated by government agencies, military organizations and business enterprises around the world.  &#8220;Geneva&#8221; support for SAML 2.0 was added in direct response to customer requests for increased cross-platform interoperability.  The benefits that are expected to accrue to customers, and the industry at large, are best summarized by Scott Cantor who is one of the key contributors to the SAML 2.0 standard and a</span><span style="font-size: 12pt; color: #1f497d; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: 'Times New Roman';"> </span><span style="font-size: 12pt; color: #000000; font-family: &quot;&quot;sans-serif&quot;&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';">Senior Systems Developer at the Ohio State University.</span></span></p>
<blockquote><p class="MsoNormal" style="margin: 0in 0.5in 0pt; line-height: 11.4pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span><em>As a Shibboleth and OpenSAML project developer, and a deployer of the Shibboleth software at The Ohio State University, I&#8217;m excited and gratified that Microsoft is implementing the SAML 2.0 Web SSO profile in its upcoming products. Throughout the life of the Shibboleth project, and my work on the SAML 2.0 standard, our goal has been to leverage open standards to foster broad interoperability in federated identity within the higher education community and between it and its many commercial and non-commercial partners. Microsoft is clearly one of those critical partners, and as a key technology supplier, its support for the SAML standard reflects an understanding of our community&#8217;s needs and goals, and will expand the scope and impact of our efforts.</em></span></p>
<div><span style="font-size: 10pt; mso-bidi-font-size: 10.5pt;"></span></div>
<p><span style="font-size: 10pt; mso-bidi-font-size: 10.5pt;"><span style="font-family: Consolas;"></p>
<p class="MsoNormal" style="margin: 0in 0.5in 0pt; line-height: 11.4pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span><em>Our users will benefit by obtaining access to the broadest potential set of federated applications and services, and our worldwide community will benefit from the opportunity to deploy Microsoft&#8217;s identity solutions with the knowledge that they will interoperate with Shibboleth. Microsoft&#8217;s willingness to listen to our requirements and suggestions demonstrates a commitment to real-world compatibility. I look forward to continuing the dialog with Microsoft as we drive further interoperability in the use of federation metadata to scale and simplify both SAML 2.0 and WS-Federation deployments.</em></span></p>
<p></span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0.5in 0pt; line-height: 11.4pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"> </p>
<p></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://identity-des.com/microsoft-geneva-server-supports-saml-20/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>DIDW: A Claims Based Architecture for British Columbia</title>
		<link>http://identity-des.com/didw-a-claims-based-architecture-for-british-columbia/</link>
		<comments>http://identity-des.com/didw-a-claims-based-architecture-for-british-columbia/#comments</comments>
		<pubDate>Fri, 28 Sep 2007 15:16:01 +0000</pubDate>
		<dc:creator>Don Schmidt</dc:creator>
				<category><![CDATA[ADFS]]></category>
		<category><![CDATA[CardSpace]]></category>
		<category><![CDATA[Federated Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Web Services Standards]]></category>

		<guid isPermaLink="false">http://identity-des.com/2007/09/28/didw-a-claims-based-architecture-for-british-columbia/</guid>
		<description><![CDATA[This session was delivered by Ian Bailey (Director of Application Architecture, Office of the CIO, Provence of British Columbia, Canada) at Digital ID World in San Francisco.  A compelling session in its own right, it was also the coming out party for the BC Identity Management Architecture Project. The provincial government leadership has taken a bold step to provide [...]]]></description>
			<content:encoded><![CDATA[<p>This session was delivered by Ian Bailey (Director of Application Architecture, Office of the CIO, Provence of British Columbia, Canada) at <a href="http://www.digitalidworld.com/">Digital ID World </a>in San Francisco.  A compelling session in its own right, it was also the coming out party for the <a href="http://www.cio.gov.bc.ca/idm/">BC Identity Management Architecture Project</a>.</p>
<p>The provincial government leadership has taken a bold step to provide better outcomes for BC citizens through the use of online services and advanced identity management technology, such as Information Cards.  They organized a working group of government agencies and vendors to define an architecture that will enable critical, online access to services provided by the government and the broader public sector, while protecting the privacy of BC citizens.  The <a href="http://www.cio.gov.bc.ca/idm/">website</a> spells out the scope and vision of the project.</p>
<blockquote><p>The Office of the Chief Information Officer (OCIO) for the Province of British Columbia, with the advice and counsel of an executive committee of Broader Public Sector (BPS) Chief Information Officer&#8217;s (or equivalent), and key industry leaders have collaborated to develop an architecture that would enable an identity management service for the government and the BC BPS.</p>
<p>The goal of this project is to develop an identity management architecture to enable interoperation across a diverse range of public sector organizations and their service providers using multiple vendors’ technology solutions.</p></blockquote>
<p>I have had the privilege to participate in this project. It has been an exhilirating experience to work with peers from so many BC government agencies and leading vendors in the identity management space. In addition to Ian, I especially want to congratulate Dave Nikolejsin (CIO) and Peter Watkins (Executive Director, Office of the CIO) for their vision and energy. And I want to thank <a href="http://identity20.com/?p=111">Dick Hardt </a>(CEO, Sxip Identity) for leading us in the development of a Claims Based Identity Management Architecture that I personally believe will become a model for governments and the broader public sector everywhere. This quote from the introduction of the <a href="http://www.cio.gov.bc.ca/idm/">Architecture Document </a>should explain my enthusiasm.</p>
<blockquote><p>Over the past three decades, the British Columbia Provincial Government and Broader Public Sector (BPS) organizations have invested heavily in the automation of business processes. Much of this investment has taken place only to meet a single organization’s unique local needs. It was usually done with limited consideration towards building interoperable cross-organizational information architecture.</p>
<p>To achieve the broader goals of the Province and improve service delivery, a mechanism must be created to securely share information between organizations and systems. An important piece of this mechanism is the development of common cross-organizational standards for interoperable identity management.</p>
<p>This is a complex issue to resolve when one considers the spectrum of public and private sector stakeholders involved: policy, management and administrative issues; privacy and security requirements for the management of access to information; and the various technologies in place. Compounding this architectural challenge is the fact that the Information Technology industry does not have an inclusive “off the shelf” solution. This project will require the British Columbia public sector to work with industry to build upon existing international standards in the development of a business and technology architecture to meet the secure information sharing needs of the BPS.</p></blockquote>
<p>There is so much more I would like to share with you about this project. It is a profound endorsement of the industry wide convergence on Information Card technology and the underlying WS-* protocols and web services architecture. However, I have to catch another plane. So let me leave you with the knowledge that the BC government has also announced that they are taking the next step and moving the Identity Management Architecture Project from concept to reality. In his session, Ian described a <a href="http://www.cbc.ca/technology/story/2007/09/25/bc-identity.html?ref=rss#skip300x250">pilot project </a>that is expected to get underway this year.</p>
]]></content:encoded>
			<wfw:commentRss>http://identity-des.com/didw-a-claims-based-architecture-for-british-columbia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

