June 26, 2003

Web services ID management touted

Service Provisioning Markup Language will be demonstrated in July

Web services identity management from OASIS (Organization for the Advancement of Structured Information Standards) will be showcased at the Catalyst Conference in San Francisco in July, OASIS said on Thursday.

The first public demonstration of the OASIS Service Provisioning Markup Language Specification (SPML) Version 1.0 will be held on July 9, according to the organization. SPML is an XML-based framework for exchanging and administering user access rights and resource information across heterogeneous environments. Ten OASIS members will show the stability of the specification and demonstrate interoperability between SPML-conformant products, according to OASIS.

The specification provides a mechanism for exchanging information between provisioning service points on the Internet, OASIS said. It is designed to work with SOAP, SAML (Security Assertion Markup Language), and the OASIS WS-Security specification.

Among vendors endorsing the specification are BMC Software, Business Layers, Entrust, OpenNetwork, PeopleSoft, Sun Microsystems, Waveset, Thor Technologies, and TruLogica, according to OASIS.

SPML currently is undergoing public review in the OASIS process for consideration of standards.

An analyst in an e-mail response to questions stressed the importance of identity management but added that SPML could overlap with other specifications.

"SPML adds to the identity management capabilities by providing a standard way in which access to these critical infrastructure resources can be granted or denied," said analyst Ronald Schmelzer of ZapThink in Waltham, Mass. "This means that companies can build applications that have strict identity and security policies without having to do so in a proprietary and noninteroperable manner."

"While SPML has more to do with provisioning physical access to specific resources, there is definitely potential for overlap or at least complementary offering to the WS-Security and WS-Policy specifications," Schmelzer said.

Paul Krill is an editor at large at InfoWorld.
Close

On Twitter now

Architecture

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Architecture Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2009 Infoworld, Inc.