Finally, OASIS announced last week that it is calling for participation for Web Services Federation. The formation of the WS-Federation Technical Committee is announced here.
WS-Fed is an important addition to the WS-* protocol suite that enables users to sign-in seamlessly to systems outside of their own organization without requiring (more) new usernames and passwords using Single-Sign-On (SSO) between separate organizations with an established trust relationship.
WS-Fed builds upon and composes with other WS-* protocols:
- WS-Fed extends WS-Trust
- WS-Fed composes with WS-Security and WS-SecureConversation to ensure data integrity and privacy
- WS-Fed composes with WS-MetadataExchange and WS-Policy to enable simple provisioning and trust relationship configuration
Does WS-Fed compete with Liberty SAML?
- Both SAML and WS-Fed enable browser-based identity federation (Passive-Mode)
- However, WS-Fed enables a superset of scenarios, including:
- Seamless federation with Web Services and/or Rick-Client applications
- Separation of identities, token types, protocols and encodings
- Multi-purpose Security Token Service (STS) that can return tokens stating different assertions based upon the scenario
WS-Fed adds identity federation capabilities to the existing WS-* suite of protocols resulting in:
- A single protocol stack that supports the majority of your needs and scenarios
- Simplified development, deployment, management and control
The formation of the Technical Committee to drive the standardization of the WS-Fed is an important step in evolution of the industry-wide effort to create a single, comprehensive communication protocol suite that enables many current and new scenarios most effectively.