« Identity Services: Tackling Authorization | Main | SPML: Life Support Redux »

February 01, 2010

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83420ad7a53ef0120a83c8f43970b

Listed below are links to weblogs that reference SPML Is On Life Support ….:

Comments

Anil John

Really glad to see this discussion starting. From an end user perspective SPML is most definitely needed to implement an open and standards based provisioning interface. And there are many use cases that would benefit from it.

The concern with exposing LDAP/AD across organizational boundaries is real and may not be resolved at the technology level. Applying an existing cross-cutting security infrastructure to a SOAP binding (to SPML) is a proven and understood mechanism which is more acceptable to risk averse organizations.

I would also add two additional points:

1) More support for the XSD portion of SPML vs. DSML in vendor tooling. There are a LOT of authoritative sources of information that are simply NOT directories.

2) There needs to be the the analog of SAML metadata in the SPML world (Or a profile of SAML metadata that can be used with SPML) to bootstrap the discovery of capabilities. The "listTargets" operation is simply not enough.

The comments to this entry are closed.

  • Burton Group Free Resources Stay Connected Stay Connected Stay Connected Stay Connected



Blog powered by TypePad