« Sometimes you just HAVE to see if it’s really HOT… | Main | Kerberos interop event hosted by Microsoft! »

January 07, 2009

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83420ad7a53ef010536b1c8eb970b

Listed below are links to weblogs that reference Down with federated provisioning:

Comments

Dr Joe in NH

SPML is terrible spaghetti at best. Having worked for a SaaS org, we looked at it and decided it was overkill for something that could be done in a much more compact and simple fashion. (We rolled our own). Some SaaS providers certainly have more than a clue about provisioning (witness Google's provisioning APIs) but I agree that it's not widespread and usually an afterthought.

byron arnao

Given these shortcomings ... SPML not being optimal, roll your own approaches leading to non-standard interfaces there does seem to be a vacuum in terms of a standard and opportunity for a vendor/company/standard to evolve to act as the glue for this. Is it simply that the demand does not exist or does not exist YET?

Chandra

We do need a standard way of provisioning. If SPML is complex and has shortcomings, there needs to be a simplified version of it. S2PML (Simplified SPML)???

KeithD

Federated Provisioning? What's the point? Provisioning is performing the necessary administration in the service provider's environment to allow identity to use the service. For example creating a folder for files, a mailbox , defining access rights and assiging passwords.

Surely the goal of Federation is to avoid this administration. If you need something, then assemble it "on the fly" when the user first uses the service.

Using SAML pseudonyms that should all be possible, in theory at least. I'm quite prepared to accept that in practice it will be difficult to collect all the information you need "on the fly" - but I'd suggest that that is because the IP does not have it or cannot/will not release it.

We have two problems
- who are the Identity Providers we will trust as custodians of our information.
- how (when) does the SP deprovision a stale account.

The comments to this entry are closed.

  • Burton Group Free Resources Stay Connected Stay Connected Stay Connected Stay Connected



Blog powered by TypePad