|
|
|
|
|
Third in Sun Developer Network tech author Marina Sum's series of interviews with Sun's identity team is Daniel Raskin, senior product line manager for access and federation management at Sun. Daniel lifts the lid on some of the cool new features coming up in Sun Federated Access Manager 8.0 (and, of course, available NOW in OpenSSO) specifically designed to simplify federation deployments, including Fedlets, Virtual Federation, the Federation Validator and more. |
|
If you've taken a look at federated identity, but become bogged down in acronyms (SSO, SP, SAML???) and jargon (why do I need an identity provider? I already have an identity), then you'll be happy to read identity diva Eve Maler's recent article on the topic - Federated Identity Through the Eyes of the Deployer. Eve and regular SDN identity writer Marina Sum walk you through the basics of federated identity - what it is, why you might want it and what questions to ask as you architect a federated identity system. |
If you're wondering about the illustration - Eve is an authority on matters XML, being instrumental in the creation of XML and related standards such as SAML - in fact, you can blame Eve for some of those acronyms
|
Pat reports on the first build of FAM 8.0 as part of the OpenSSO community. This will provide convergence with Access Manager and Federation Manager features, in an Open Source model, like GlassFish. Check out the architecture (blog, wiki) and the roadmap (blog, diagram). New features include much improved usability, Access and Federation Manager Features, Identity Services and Web Services Security - more details here. |
Download it here, play with it and give feedback at the USERS list. I think FAM/OpenSSO will have a big impact on the industry; check it out.

Over at Superpatterns, I've just announced the first drop of my SAML 2.0 PHP service provider code. There is more detail at that link, particularly in the linked docs, but, briefly, this is a collection of PHP scripts that SAML 2.0 enable a service provider, 'outsourcing' user authentication to an identity provider. This is very much 'proof-of-concept' code - contributions are welcomed, particularly from PHPers!