« Satyam, Auditors, and Independence | Main | Relationship Paper Now Freely Available »

February 04, 2009

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83420ad7a53ef011168487c52970c

Listed below are links to weblogs that reference Will the “real” federated provisioning please stand up?:

Comments

KeithD

I understand your worries here, but in many low risk environments you can live with them. Firstly, as long as we have federation for authentication, the ex-employee cannot get into the SP account since his employer will presumably refuse the authentication request. So you just have some old files floating around at the SP that can't be accessed. Secondly, you could agree to delete the account if unused for x months. Thirdly, you could delete on the first refusal of the IdP to authenticate the user.

The problem is that Federation and Provisioning are different beasts - stop trying to get them to breed.

Dave S

I agree SAML assert purely cater to authentication and adding payload of provisioning is not really scalable but a hack. Think XACML 3.0 shows more federation capability and promise.

The comments to this entry are closed.

  • Burton Group Free Resources Stay Connected Stay Connected Stay Connected Stay Connected



Blog powered by TypePad