Burton Group's Catalyst Conference to Showcase First Demonstration of SAML 1.0 Industry Standard.Business Editors/High-Tech Writers SALT LAKE CITY--(BUSINESS WIRE)--June 3, 2002 OASIS-Sponsored Demo Features Standards-Based Interoperability Between Vendors' Diverse Security Solutions Burton Schedules SAML (Security Assertion Markup Language) An XML-based format from OASIS for exchanging security information for single sign-on. The "assertions" are statements from a SAML authority that authenticate a user, confirm some attribute about the individual and grant or 1.0 Telebriefing for June 12 Burton Group, a technology-industry pioneer of network research and consulting, will showcase the first public demonstration of standards-based interoperability among SAML 1.0-conformant security software products on July 15 at its annual Catalyst Conference. Sponsored by the Organization for the Advancement of Structured Information Standards (OASIS), the industry standards group that developed the proposed Security Assertion Markup Language markup language Standard text-encoding system consisting of a set of symbols inserted in a text document to control its structure, formatting, or the relationship among its parts. The most widely used markup languages are SGML, HTML, and XML. (SAML) standard for Web services (1) Loosely, any online service delivered over the Web. Such usage appears in articles from non-technical sources, but not in IT-oriented publications, because definition #2 below describes the correct use of the term. security, the demonstration will feature products from several network security software vendors. SAML 1.0 is a proposed OASIS standard for exchanging authentication and authorization information among disparate Web access management and security products. SAML 1.0, which will soon come up for a vote by the full OASIS membership, addresses the need for secure single sign-on An identification system that lets users log into multiple Web sites on the Internet with one username and password. Single sign-on systems are also used within an enterprise, enabling users to access all authorized resources in the local network using the same username and password. (SSO See single sign-on and CSO. SSO - single sign-on ) across diverse Web access management environments implemented across various organizations, applications, Web sites and portals. The proposed standard defines standardized exchanges of identity and access management (IAM IAM - Interactive Algebraic Manipulation. Interactive symbolic mathematics for PDP-10. ["IAM, A System for Interactive Algebraic Manipulation", C. Christensen et al, Proc Second Symp Symb Alg Manip, ACM Mar 1971]. ) information, leveraging such Web services standards as XML XML in full Extensible Markup Language. Markup language developed to be a simplified and more structural version of SGML. It incorporates features of HTML (e.g., hypertext linking), but is designed to overcome some of HTML's limitations. and SOAP. "SAML is an important security interoperability initiative," said James Kobielus, senior analyst at Burton Group. "Most Web access solution vendors have committed resources to the emerging standard and are in the process of implementing SAML 1.0 in the next releases of their products. OASIS' SAML interoperability demonstration will prove the standard's viability in practice." "This interoperability demonstration is a milestone in the development and recognition of the SAML 1.0 specification as an open standard," said Prateek Mishra, director of technology at Netegrity, member of the OASIS Security Services Security services are state institutions for the provision of intelligence, primarily of a strategic nature, but also including protective security intelligence. Examples include the Security Service (MI5) and the Secret Intelligence Service (MI6) in the United Kingdom, and the Technical Committee (SSTC SSTC Security Services Technical Committee SSTC Services Fédéraux des Affaires Scientifiques, Techniques et Culturelles (Belgium office for scientific, technical and cultural affairs) SSTC Solid State Tesla Coil ) and editor of the SAML 1.0 Bindings Specification. "We are pleased with how the industry came together to develop SAML 1.0 and how quickly vendors are implementing the new standard in their products." The SAML interoperability demonstration will involve several current and future commercial software solutions that support Web SSO, access management and other network security services Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. NSS provides a complete open-source implementation of crypto libraries supporting SSL and S/MIME. . As of May 15, 2002, vendors who have indicated their intention to participate in the event are Baltimore Technologies Baltimore Technologies was an internet security firm founded in 1976 by Michael Purser. It was acquired in 1996 by a team financed by Dermot Desmond and led by Fran Rooney, who became CEO. , Crosslogix, Entegrity Solutions, ePeople, Novell, OverXeer, Netegrity, Oblix, RSA Security RSA, The Security Division of EMC Corporation, is headquartered in Bedford, Massachusetts, and maintains offices in Ireland, the United Kingdom, Singapore, India, and Japan. RSA organizes the annual RSA conference. , Sigaba, Sun Microsystems Sun Microsystems, Inc. (NASDAQ: JAVA[3]) is an American vendor of computers, computer components, computer software, and information-technology services, founded on 24 February 1982. and Tivoli Systems. The SAML 1.0 demonstration will feature cross-enterprise SSO across several vendors' Web access management products, which will support consistent vendor implementations of the SAML 1.0 Web Browser The program that serves as your front end to the Web on the Internet. In order to view a site, you type its address (URL) into the browser's Location field; for example, www.computerlanguage.com, and the home page of that site is downloaded to you. profile. In particular, the event will demonstrate the following scenarios: -- IAM interoperability - Businesses using different vendors' Web access management products establish trust relationships for the purpose of sharing authentication, attribute and authorization decision information. -- Cross-enterprise Web single sign-on - Browsers/users authenticate at "portal" sites and then are able to access Web resources managed under other "content" sites. (The latter sites continue to manage authorization of access to their content. Technically, this will involve bilateral interoperability between different vendors' Web access management platforms with "source" servers operating as portals that provide access to resources at one or more "destination" servers. Users will be able to leverage an assertion produced at their source server over one or more destination servers in the context of a single SSO session.) Additionally, OASIS SSTC co-founder and participant Hal Lockhart, security architect for Entegrity Solutions, will present a progress report on the SAML 1.0 standard on Tuesday, July 16 at Catalyst Conference. Lockhart will discuss SAML 1.0's status, review the scope and objectives of the previous evening's industry interoperability demonstration, and discuss future directions in the development of the SAML standard. Information about Catalyst Conference is located at www.burtongroup/catalyst. NOTE TO PRESS ONLY: Burton Group is offering complimentary Catalyst Conference registration to members of the media. A press conference on SAML interoperability will be held at Catalyst Conference on July 15 prior to the demonstration. Members of the media: To register for Catalyst Conference or for information about the SAML press conference, contact Thomas Aitchison (taitchison@socketpr.com or 512/335-8771 ext. 15). SAML 1.0 TeleBriefing: Wednesday, June 12, 2002 at 12 p.m. ET Burton Group will hold a TeleBriefing on Security Assertion Markup Language 1.0 on June 12 at 12 p.m. Eastern Time. Burton senior analyst James Kobielus will clarify the details of the SAML 1.0 standard, which is on the verge On the Verge (or The Geography of Yearning) is a play written by Eric Overmyer. It makes extensive use of esoteric language and pop culture references from the late nineteenth century to 1955. of ratification by the Organization for the Advancement of Structured Information Standards (OASIS). Kobielus will also discuss deployment and integration issues surrounding use of SAML in distributed security environments and vendors' plans to implement SAML 1.0 in their products this year. To register, send e-mail to clientservices@burtongroup.com, or call 800/824-9924 ext. 174 (International calls, dial 801/304-8174). About OASIS (www.oasis-open.org) OASIS (Organization for the Advancement of Structured Information Standards) is a not-for-profit, global consortium that drives the development, convergence and adoption of e-business standards. Members themselves set the OASIS technical agenda, using a lightweight, open process expressly designed to promote industry consensus and unite disparate efforts. OASIS produces worldwide standards for security, Web services, XML conformance, business transactions, electronic publishing An umbrella term for non-paper publishing, which includes publishing online or on media such as CDs and DVDs. , topic maps Topic Maps is an ISO standard for the representation and interchange of knowledge, with an emphasis on the findability of information. The standard is formally known as ISO/IEC 13250:2003. and interoperability within and between marketplaces. OASIS has more than 400 corporate and individual members in 100 countries around the world. OASIS and the United Nations jointly sponsor ebXML, a global framework for e-business data exchange. OASIS operates XML.org, a community clearinghouse for XML application schemas, vocabularies and related documents. OASIS hosts The XML Cover Pages, an online reference collection for interoperable markup language standards. About Burton Group (www.burtongroup.com) A technology-industry pioneer, Burton Group is the only company to offer integrated research, advisory and consulting services, which are critical to Global 2000 enterprises planning the evolution of their network and applications infrastructure. Burton consultants and analysts champion vendor-independent viewpoints as they guide IT professionals in the strategy of building and the tactics of managing scalable, secure, efficient networks. Burton has specialized in network-technology research and analysis since its formation in 1990. The company predicted and defined the role that meta-directory plays in an enterprise. Today, Burton continues to anticipate the direction of key networking technologies and guide the decision-making process for almost half the Fortune 100 and other global clients. About Catalyst Conference (www.burtongroup.com/catalyst) Burton Group's Catalyst Conference is an annual, three-day event three-day event a competition in the pleasure horse sport comprising usually one day each for dressage, cross country and show jumping. that focuses on relevant, critical network- and applications-infrastructure issues. The only conference of its kind, Catalyst brings together vendors, end users and analysts/consultants in a dynamic and intimate forum. This industry-shaping conference is well known for its end-user-driven agenda, intense focus and high-profile speakers. Since the first conference in 1993, Catalyst has reinforced Burton's reputation for substance, timeliness, credibility and integrity. For more information about Catalyst and speaking or hospitality suite opportunities, visit www.burtongroup.com/catalyst or e-mail catalyst@burtongroup.com. Catalyst North America North America, third largest continent (1990 est. pop. 365,000,000), c.9,400,000 sq mi (24,346,000 sq km), the northern of the two continents of the Western Hemisphere. , which is sponsored by Network World and the Network Applications Consortium (www.netapps.org), will be held at the Hilton San Francisco, July 15-17, 2002. Catalyst Europe, which is also sponsored by the NAC See network access control. , will be held at the Arabellasheraton in Munich, Sept. 24-26, 2002. |
|
||||||||||||||

Printer friendly
Cite/link
Email
Feedback
Reader Opinion