Next in thread →
Next in month →
Minutes RSA 2010 Interop Technical Call - January 19th, 2010
We also need to have a standard way to inject the attributes from the client at run time. We may use Claims again, as a child of RST, but with a different Dialect and syntax, e.g. Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context The element may like this: <t:Claims Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context" xmlns:xspa="http://schemas.xmlsoap.org/ws/xspa/claims"> <xspa:ClaimType Uri="urn:oasis:names:tc:xspa:1.0:subject:purposeofuese"> <xspa:Value>Emergency Treatment</xspa:Value> <xspa:Value>Healthcare Treatment</xspa:Value> </xspa:ClaimType> </t:Claims> WS-Federation also defines an element auth:AdditionalContext as a child of RSA that can be used for this purpose. But I am not the support for this is mature enough to use it. Thanks! Jiandong Jiandong Guo wrote: Duane DeCouteau wrote: Action Items Daniel - Provide most recent copy of HIMSS 2009 XACML policy Duane - post policy to WIKI. Duane - Publish on WIKI the attributes required in request from client (XSPA Requestor), and those requested from PIP Jiandong - will update XSPAInterop wsdls WS-Policy with those required attributes Attached is a sample wsdl with policy. Here the protection token is the service x509 certificate. There are two endorsing tokens (the ones supplied by the client) IssuedToken (from STS) and an X509 certificate ( I changed from SupportingToekn to EndorsingSupportingToken to make sure it is passed it passed in a secured way). For IssuedToken I add a sample Claims to indicate to client what the attributes required to access the service. I made up some url to illusttrate. Thanks! Jiandong Duane - To define and publish on WIKI where opportunities from WS-Trust vendors to plug-in services into existing applications Duane/Emory Fry - Discuss plans for exposing testbed from KMR Arizona development site. --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
Next in thread →
Next in month →