Enterprisey thoughts – John Gøtze
Posts tagged Web services
Project NemFORM
Feb 14th
The Danish Government Business Reference Model - FORM (in Danish) – is an overview of what the Danish public administration does, which services it provides, and which legislation that regulates these services.
I have been ‘playing around’ with the dataset FORM makes up. In the blog menu, you will find links to pages about Project NemFORM.
To demonstrate how the reference model can be used, I have created this simple application (autosuggesting services; reference), which can also be used on a mobile device (tested on Android only, so far).
If you are interested in the geeky details, read about my experience with FORM XML, and JQuery-empowered FORM usage. You can also read about my implementation of the new FORM widget from Digitaliser.dk.
My project is mentioned in a news story on Modernisering.dk, the Ministry of Finance’s website for digitization of government (and owners of FORM). ‘Innovative use’, they call my project. How nice of them
Full disclosure: The Ministry of Finance is a client of EA Fellows. NemFORM is however a private project of mine.
Microsoft and Danish Government in New Identity Deal
May 12th
A year ago, my former collegue Søren Peter Nielsen wrote, on behalf of the Danish government, a letter to Microsoft. Seems he got a response, and I’m sure it’ll interest XMLGrrl and many others, that an announcement was made yesterday: Agreement between the National IT and Telecom Agency and Microsoft: Agreement concerning partial support of the SAML 2.0 standard.
“The ongoing dialog between the National IT and Telecom Agency and Microsoft has resulted in an agreement on partial support of the SAML 2.0 standard in Microsoft’s forthcoming version of their federation product named Active Directory Federation Services 2″, the agency writes.
The text agreed upon is as follows:
“The Danish public sector has chosen SAML 2.0 as their federation standard. Microsoft products use WS-Federation and WS-Trust as the foundation of their federated identity architecture. The Danish government has agreed that the SAML 2.0 token format is sufficient to provide basic interoperability between WS-Federation and SAML 2.0 environments as a common assertion format, without loss of authentication integrity.
To support interoperability between WS-Federation and SAML 2.0 based products Microsoft has agreed to support the SAML 2.0 token format in the future release of Active Directory Federation Services code-named Active Directory Federation Services “2″. Microsoft will provide the Danish public sector Centre of Service Oriented Infrastructure with pre-release code to help analysis and planning of solutions for integrating WS-Federation-based clients in the Danish federation, and to collect feedback on the feature implementation.
In addition, the co-authors of WS-Federation (including Microsoft) have submitted the specification to OASIS for standardization. This step further enables interoperability between federated environments that deploy SAML 2.0-based products and those that deploy WS-Federation-based products.”
In commenting the agreement, the agency writes: “With this agreement a possibility for inclusion of Microsoft based clients in a common public SAML 2.0 based federation has opened”, and notes:
The integration will require the standard based login solutions to be expanded with a special integration code. The solution is therefore a pragmatic tactical integration solution, but with the above-mentioned partial SAML 2.0 support from Microsoft it is expected that the integration can be done without influencing the individual “Microsoft Active Directory Federation Service†user organizations.
The agency notes that more iinformation on the concrete possibilities will be published as the National IT and Telecom Agency’s Centre for Service Oriented Infrastructure receives pre-release code from Microsoft that can be integration tested.
The agency elaborates a bit more on the deal:
It is still desired, that Microsoft support all of the SAML 2.0 standard in their products, but the above-mentioned agreement are a good first step towards more convergence among standards for transverse user management.
The National IT and Telecom Agency also sees the filing of the WS-Federation (WS-FED) specification for standardization in OASIS as a step that can promote convergence among federation standards.
It should be stressed that it does not mean that the WS-Federation specification is recommended equally to SAML 2.0 for common public solutions.
When the results of the standardization with WS-Federation become available (expectedly in the end of 2008) it might be relevant to do a new assessment but for now the SAML 2.0 it is still the only standard, which is recommended as a federation standard for Danish common public solutions.
So, there we have it.
I want to congratulate Søren Peter on a job well done. Stand firm on SAML 2.0, the open ecosystem needs it. And thanks to Microsoft for listening to customers (but why only partial support?).
Conference Time
May 10th
I’ll be attending a few conferences as a member of the Press in the coming weeks, so if you’re there too, and want to meet up, do get in touch.
On Sunday, I’ll leave for Vienna for SAPPHIRE 2007. “Business at the speed of change“. It’ll be interesting to hear more about where SAP is with SOA and much more, but frankly, the presentation I look forward to the most is the one by Geoffrey Moore, on Business Network Transformation to Create Competitive Advantage.
Then in June, I’ll go to Orlando for the IBM Rational Software Development Conference 2007. “What Keeps Me Rational?”. I think I’ll focus on architectural issues, and it seems there will be talk about both SOA and EA. It’ll also be interesting to hear about where Danny Sabbah is with Jazz.
Standards, Security, and Sectors
Oct 27th
I’m going – are you? The third annual OASIS Adoption Forum is held in London on 27-29 November. The forum is themed Enabling Efficiency between Government, Business and the Citizen: Managing Secure Interactions in Sector Applications, and the list of presenters is very impressive. Also note that a Workshop on the State and Future of PKI has just been announced being part of the event. There will be sessions about adoption of OASIS standards such as SAML, XACML, and WS-Security.
OASIS Adoption Forum “seeks to educate and expose security leaders and professionals to the tools, standards and implementations that are transforming security interactions and relationships between citizens, businesses, governmental institutions and agencies. With increasing threats encompassing everything from hacking to identity theft, providing a secure environment must be a major objective for companies, governments, and organizations worldwide. The success you enjoy tomorrow depends on the security decisions you make today”.













Recent Comments