Read up on the latest ideas and technologies from companies that sell hardware, software and services. Did you GET the memo? Getting you from Web 1.0 to Web 2.0 Security
Market Trends: Multienterprise/B2B Infrastructure Market | Worldwide | 2008
Email Archiving Implementation: Five Costly Mistakes to Avoid
Web Security SaaS: The Next Generation of Web Security
Cutting printer costs
How to Beef Up Your Sales Pipeline
Dude! You Say I Need an Application-Layer Firewall?!
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
The OASIS Internet standards consortium said Monday that its members ratified SAML (Security Assertion Markup Language) Version 1.1 as an official standard, approving changes to the specification will improve interoperability with other Web services security standards.
The vote assigns the highest level of OASIS (The Organization for the Advancement of Structured Information Standards) ratification to SAML 1.1 and could open the door for wider adoption of the XML (Extensible Markup Language) framework for companies using Web services to conduct high value transactions, according to Prateek Mishra of Netegrity Inc., co-chair of the OASIS Security Services Technical Committee.
SAML is a standard that supports so-called "federated identity" systems in which user authentication and authorization information is securely exchanged between Web sites within an organization or between organizations. SAML enables a user to sign on once to Web-enabled services, instead of having to repeatedly log in when they move from one Web site or Web-enabled application to another.
The SAML 1.0 standard, which was approved in November 2002, is widely in use by major corporations including The Boeing Co. and Fidelity Investments Inc., Mishra said.
The new version of SAML includes a number of updates and fixes for problems identified in the 1.0 standard, he said.
In particular, SAML 1.1 revised guidelines for the use of digital certificates to sign SAML user authentication exchanges, known as SAML assertions. SAML 1.0 standards were vague about how to digitally sign SAML assertions, creating interoperability problems between different companies implementing Web services using the 1.0 standard, Mishra said.
Only a "small group" of companies are currently interested in using digital certificates to sign SAML assertions. However, that group is growing, as companies look for ways to exchange sensitive data with employees and business partners while also verifying that digital transactions took place -- a capability known as "nonrepudiation," he said.
"I think people are definitely getting interested in using SAML for higher value transactions. Organizations want a signed form of nonrepudiation, and we definitely see that as a step towards wider adoption (of SAML), " Mishra said.
Having handed off the SAML 1.1 standards, OASIS's Security Services Technical Committee is now at work on the SAML 2.0 specification, Mishra said. That version will come with major additions to the standard based on feedback from large companies.
Among other things, the group is looking at ways to implement distributed log out, in which three or more Web sites that share a single login session will synchronize when a user terminates that session.
OASIS also wants to harmonize SAML 2.0 with the Liberty Alliance's ID-FF layer, another federated identity, single-sign on standard, Mishra said.
In a related announcement, RSA Security Inc. said Monday that a new version of the ClearTrust Web access management product includes support for user authorization and authentication using SAML Version 1.1 assertions.
ClearTrust Version 5.5 contains features for generating and processing SAML 1.1 assertions, the company said.
Other new features include Web-based administration of user identities, authentication mapping between Web sites and digital signature and certificate validation.
New management features that use technology licensed from Thor Technologies Inc. improve the ability of users to manage their own login account and password, group membership and user profile, RSA said.
Earlier versions of ClearTrust supported the SAML 1.0 standard, according to an RSA spokeswoman.
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
The management of Microsoft® Exchange storage growth is the most challenging problem facing Exchange administrators. Because of the popularity of email as a communication technology, and because users tend to keep email, maintaining adequate storage on the Exchange Server is a constant challenge. Learn how to maintain the space you need by reading on.









