About UsCommunityTrainingContent DevelopmentContact

Blogs
Pluralsight
Course Schedule
Scott Allen
Craig Andera
Mark Baciak
Don Box
Keith Brown
John CJ
Tim Ewald
Jon Fancey
Jon Flanders
Vijay Gajjala
Kirill Gavrylyuk
Ian Griffiths
Martin Gudgin
Jim Johnson
John Justice
Mike Henderson
Joe Hummel
Matt Milner
Ted Neward
Fritz Onion
Brian Randell
Jeffrey Schlimmer
Aaron Skonnard
Dan Sullivan
Herb Sutter
Doug Walter
Jim Wilson
Mike Woodring

My Links
Home
Contact
Login

Blog Stats
Posts - 72
Stories - 0
Comments - 149
Trackbacks - 39

Bloggers
Don Box(rss)
Jeff Schlimmer(rss)

Archives
Mar, 2008 (1)
Nov, 2007 (1)
Jun, 2006 (1)
May, 2006 (2)
Apr, 2006 (2)
Nov, 2005 (1)
Oct, 2005 (1)
Sep, 2005 (4)
Aug, 2005 (8)
Jul, 2005 (2)
Jun, 2005 (2)
May, 2005 (9)
Apr, 2005 (3)
Mar, 2005 (2)
Feb, 2005 (1)
Jan, 2005 (8)
Nov, 2004 (7)
Oct, 2004 (15)
Sep, 2004 (2)

Post Categories
Bikes(rss)
Indigo(rss)
Personal(rss)
Protocols(rss)
Sailing(rss)
Security(rss)
Work(rss)
XAML(rss)

Image Galleries
CBR600FY Parts
MVP Summit, Rio de Janeiro, 2004
My CBR600
Travel Photos



Much of the last year of my life has been spent working on the WS-SecurityPolicy spec, which was republished today. This version is significantly different from the previous one. Here are the highlights;
 
  • Formalized notion of a security binding
  • Specific bindings for transport level security and both symmetric and asymmetric key based message level security
  • Support for many different token types including federated tokens
  • Mechanism for specifying additional tokens
  • Support for specifying various WSS 1.0, WSS 1.1 and WS-Trust options
posted on Wednesday, July 13, 2005 3:13 AM

  • # Link Listing - July 14, 2005
    Christopher Steen - Learning .NET
    Posted @ 7/13/2005 10:15 PM

    August
    2005 issue of MSDN Magazine now online [Via: toub ]
    Breaking
    News: New Microsoft Certification...
  • # Link Listing - July 14, 2005
    Christopher Steen
    Posted @ 7/13/2005 10:16 PM

    August
    2005 issue of MSDN Magazine now online [Via: toub ]
    Breaking
    News: New Microsoft Certification...
  • # Keeping up with the Joneses #1
    Julie Lerman Blog
    Posted @ 7/15/2005 4:40 PM
  • # re: New WS-SecurityPolicy published
    Edson Camargo
    Posted @ 2/8/2006 11:26 AM
    Hi Margin,

    My name is Edson, I am a master degree student and my research include the development of a web service aplication.

    I have a doubt about WS-SecurityPolicy specification. I think that you can help me :o)

    Let's assume the scenery where a relying part defined in your WSDL needs a SAML Token issued by a STS (WS-Trust). So, I think that the policy into WSDL should be thus:

    Syntax:
    <wsp:Policy>
    <sp:IssuedToken sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/AlwaysToRecipient">
    <sp:Issuer> <EndpointReference xmlns="http://schemas.xmlsoap.org/ws/2004/08/addressing">
    <Address>http://AdressOfTheSTS.com</Address>
    </sp:Issuer>
    <sp:RequestSecurityTokenTemplate>
    <!-- Policy defined by the Service for the STS -->
    <wst:TokenType>urn:oasis:names:tc:SAML:1.1</wst:TokenType>
    <wst:KeyType> http://schemas.xmlsoap.org/ws/2004/04/trust/SharedKey </wst:KeyType>
    </sp:RequestSecurityTokenTemplate>
    </sp:IssuedToken>
    </wsp:Policy>

    The SAML token could include an autentication statement , autorization statement or attribute statement. Let's suppose that the service need a autorization stantemente or client atribute issued by the STS into SAML token .So, the question is: how to express this policy for the STS?

    Thanks in advance,

    Edson
    Master Degree Student
    LCMI / DAS / UFSC
    88.040-900 - Brazil - Florianópolis - SC

Title  
Name  
Url
Comments   
Please enter the code you see below. what's this?
This CAPTCHA image helps deter automated scripts that submit comment spam. In essence, it helps us determine that you are indeed a human instead of script.

 
   
 
© 2004 Pluralsight.
Visual Design by Studio Creativa
Privacy Policy