Next in thread → Next in month →

Minutes RSA 2010 Interop Technical Call - January 19th, 2010

From
Jiandong Guo <>
Date
2010-01-22T20:35:00+00:00
ID
Thread
Minutes RSA 2010 Interop Technical Call - January 19th, 2010
We also need to have a standard way to inject the attributes from the
client at run time.


We may use Claims again, as a child of RST, but with a different
Dialect and syntax, e.g.

Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context


The element may like this:

<t:Claims
Dialect="http://schemas.xmlsoap.org/ws/xspa/claims/context"
xmlns:xspa="http://schemas.xmlsoap.org/ws/xspa/claims">

                                <xspa:ClaimType
Uri="urn:oasis:names:tc:xspa:1.0:subject:purposeofuese">

                                                   
<xspa:Value>Emergency Treatment</xspa:Value>

                                                   
<xspa:Value>Healthcare Treatment</xspa:Value>

                               </xspa:ClaimType>

</t:Claims>


WS-Federation also defines an element

auth:AdditionalContext

as a child of RSA that can be used for this purpose. But I am not the
support for this is mature enough to use it.


Thanks!


Jiandong




Jiandong Guo wrote:

  
Duane DeCouteau wrote:
  


Action Items

Daniel - Provide most recent copy of HIMSS 2009 XACML policy

Duane - post policy to WIKI.
Duane - Publish on
WIKI the attributes required in request from client (XSPA Requestor),
and those requested from PIP

Jiandong - will update XSPAInterop wsdls WS-Policy with those required
attributes

Attached is a sample wsdl with policy. Here the protection token is the
service x509 certificate.

There are two endorsing tokens (the ones supplied by the client)
IssuedToken (from STS) and an X509 certificate (

I changed from SupportingToekn to EndorsingSupportingToken to make sure
it is passed it passed in a secured way).


For IssuedToken I add a sample Claims to indicate to client what the
attributes required to access the service. I made

up some url to illusttrate.


Thanks!


Jiandong



  Duane - To define and publish on
WIKI where opportunities from WS-Trust
vendors to plug-in services into existing applications

Duane/Emory Fry - Discuss plans for exposing testbed from KMR Arizona
development site.


  
---------------------------------------------------------------------
To unsubscribe from this mail list, you must leave the OASIS TC that
generates this mail.  Follow this link to all your TCs in OASIS at:
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
Next in thread → Next in month →