<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>unverified claims</title>
	<link>http://unverifiedclaims.com</link>
	<description>"Trust me."</description>
	<pubDate>Tue, 04 Sep 2007 22:06:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>
	<language>en</language>
			<item>
		<title>Standards rain</title>
		<link>http://unverifiedclaims.com/2007/09/04/standards-rain/</link>
		<comments>http://unverifiedclaims.com/2007/09/04/standards-rain/#comments</comments>
		<pubDate>Tue, 04 Sep 2007 22:06:03 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/09/04/standards-rain/</guid>
		<description><![CDATA[Today WS-Policy was approved as a W3C Recommendation. With that we can now say that there are standard versions of the WS-* specifications for building secure, transactable, addressable and reliable web services that are policy driven. 
&#160;
As I see now that I never addressed my own post on WS-SecurityPolicy being up for approval as an [...]]]></description>
			<content:encoded><![CDATA[<p>Today WS-Policy was approved as a W3C Recommendation. With that we can now say that there are standard versions of the WS-* specifications for building secure, transactable, addressable and reliable web services that are policy driven. </p>
<p>&nbsp;</p>
<p>As I see now that <a href="http://unverifiedclaims.com/2007/06/05/ws-securitypolicy-member-familiarization-has-begun/">I never addressed my own post on WS-SecurityPolicy being up for approval as an OASIS standard</a> (yes it was approved)&nbsp;a brief recap of the WS-* specifications approved as standards this year seems in order.</p>
<p>&nbsp;</p>
<p><a href="http://www.jeffsoto.com/art14birthdayparty.htm" atomicselection="true"><img height="144" src="http://www.jeffsoto.com/images/artsmall_birthday.jpg" width="144" align="left"></a><a href="http://docs.oasis-open.org/ws-sx/ws-secureconversation/200512">WS-SecureConversation 1.3 OASIS Standard</a></p>
<p><a href="http://docs.oasis-open.org/ws-sx/ws-trust/200512">WS-Trust 1.3 OASIS Standard</a></p>
<p><a href="http://docs.oasis-open.org/ws-tx/wscoor/2006/06">WS-Coordination 1.1 OASIS Standard</a></p>
<p><a href="http://docs.oasis-open.org/ws-tx/wsat/2006/06">WS-AtomicTransaction 1.1 OASIS Standard</a></p>
<p><a href="http://docs.oasis-open.org/ws-rx/wsrm/200702">WS-ReliableMessaging 1.1 OASIS Standard</a></p>
<p><a href="http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702">WS-SecurityPolicy 1.2 OASIS Standard</a></p>
<p><a href="http://www.w3.org/TR/2007/REC-ws-policy-20070904/">WS-Policy 1.5 W3C Recommendation</a></p>
<p><a href="http://www.w3.org/TR/2007/REC-ws-addr-metadata-20070904/">WS-Addressing 1.0 Metadata W3C Recommendation</a></p>
<p>&nbsp;</p>
<p>Quite a list! I&#8217;m sure I&#8217;m missing some and I left some related specifications to the ones above out of the summary. Of course this all builds on top of existing standards like SOAP and WSS. </p>
<p>&nbsp;</p>
<p>Will there be more? Sure, things always continue to evolve.&nbsp;WS-Federation was just submitted to OASIS this year for example. So while this isn&#8217;t the end it is an important milestone.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/09/04/standards-rain/feed/</wfw:commentRss>
		</item>
		<item>
		<title>They got Information Cards in their Live IDs&#8230;</title>
		<link>http://unverifiedclaims.com/2007/08/29/they-got-information-cards-in-their-live-ids/</link>
		<comments>http://unverifiedclaims.com/2007/08/29/they-got-information-cards-in-their-live-ids/#comments</comments>
		<pubDate>Wed, 29 Aug 2007 17:09:19 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/08/29/they-got-information-cards-in-their-live-ids/</guid>
		<description><![CDATA[Now you can associate an Information Card with your Live ID. No more passwords! Hurray! 
Here are the details of how to configure CardSpace for use with Live ID.
Time to change the picture on my card.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://laughingsquid.com/lolburn/" atomicselection="true"><img height="116" src="http://laughingsquid.com/wp-content/uploads/addis-mug-shot.jpg" width="100" align="right"></a>Now you can associate an Information Card with your Live ID. No more passwords! Hurray! </p>
<p><a href="http://winliveid.spaces.live.com/Blog/cns!AEE1BB0D86E23AAC!931.entry">Here are the details of how to configure CardSpace for use with Live ID</a>.</p>
<p>Time to change the picture on my card.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/08/29/they-got-information-cards-in-their-live-ids/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OpenID Information Cards</title>
		<link>http://unverifiedclaims.com/2007/08/27/openid-information-cards/</link>
		<comments>http://unverifiedclaims.com/2007/08/27/openid-information-cards/#comments</comments>
		<pubDate>Mon, 27 Aug 2007 16:57:37 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/08/27/openid-information-cards/</guid>
		<description><![CDATA[SXIP has published a spec defining OpenID Information Cards. They have also put up a provider where you can get one of these cards, an RP test it with and the source. This looks like something worth playing with.
&#160;
Mike Jones has more details on how OpenID Information Cards work. 
(*sigh* - corrected link to actually [...]]]></description>
			<content:encoded><![CDATA[<p><a href="https://openidcards.sxip.com/spec/openid-infocards.html">SXIP has published a spec defining OpenID Information Cards</a>. <a href="https://openidcards.sxip.com/">They have also put up a provider where you can get one of these cards, an RP test it with and the source</a>. This looks like something worth playing with.</p>
<p>&nbsp;</p>
<p><a href="http://self-issued.info/?p=27">Mike Jones has more details on how OpenID Information Cards work</a>. </p>
<p>(*sigh* - corrected link to actually go to Mike&#8217;s post)</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/08/27/openid-information-cards/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WS-* for PHP</title>
		<link>http://unverifiedclaims.com/2007/08/27/ws-for-php/</link>
		<comments>http://unverifiedclaims.com/2007/08/27/ws-for-php/#comments</comments>
		<pubDate>Mon, 27 Aug 2007 16:19:30 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/08/27/ws-for-php/</guid>
		<description><![CDATA[Well this is cool, WSO2 just released a PHP extension to support WS-* including WS-ReliableMessaging and WS-SecurityPolicy.
]]></description>
			<content:encoded><![CDATA[<p>Well this is cool, <a href="http://wso2.com/">WSO2</a> just released <a href="http://dist.wso2.org/products/wsf/php/1.0.0/">a PHP extension to support WS-* including WS-ReliableMessaging and WS-SecurityPolicy</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/08/27/ws-for-php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Of monsters and frogs</title>
		<link>http://unverifiedclaims.com/2007/08/22/of-monsters-and-frogs/</link>
		<comments>http://unverifiedclaims.com/2007/08/22/of-monsters-and-frogs/#comments</comments>
		<pubDate>Wed, 22 Aug 2007 20:20:15 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/08/22/of-monsters-and-frogs/</guid>
		<description><![CDATA[Wow. This is an interesting description a compromise at Monster that has been used for targeted attacks. With the data that has been compromised the spam used in those targeted attacks would be pretty convincing. Apparently it stems from a few compromised customer accounts at Monster. One wonders what other accounts have been compromised through [...]]]></description>
			<content:encoded><![CDATA[<p>Wow. <a href="http://www.networkworld.com/news/2007/082007-monster-trojan.html">This is an interesting description a compromise at Monster that has been used for targeted attacks</a>. With the data that has been compromised the spam used in those targeted attacks would be pretty convincing. Apparently it stems from a few compromised customer accounts at Monster. One wonders what other accounts have been compromised through this attack. <a href="http://michaelzimmer.org/2007/08/19/41-of-facebook-users-share-personal-information-with-a-frog/">One wonders if any of the owners of the initially compromised accounts were friends with a frog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/08/22/of-monsters-and-frogs/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WS-SecurityPolicy member familiarization has begun</title>
		<link>http://unverifiedclaims.com/2007/06/05/ws-securitypolicy-member-familiarization-has-begun/</link>
		<comments>http://unverifiedclaims.com/2007/06/05/ws-securitypolicy-member-familiarization-has-begun/#comments</comments>
		<pubDate>Tue, 05 Jun 2007 04:55:30 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/06/05/ws-securitypolicy-member-familiarization-has-begun/</guid>
		<description><![CDATA[ WS-SecurityPolicy is a keystone in enabling secure web services. This specification provides a set of WS-Policy assertions for describing the desired security characteristics of web service messages. More specifically it provides the ability for the expression of requirements related to WSS, WS-SecureConversation and WS-Trust. This specification has been under development within the OASIS WS-SX [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Keystone_%28architecture%29" atomicselection="true"><img alt="SP is number 1, the keystone" src="http://upload.wikimedia.org/wikipedia/commons/thumb/e/e4/Arch_illustration.svg/300px-Arch_illustration.svg.png" align="right"></a> <a title="WS-SecurityPolicy" href="http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702">WS-SecurityPolicy</a> is a keystone in enabling secure web services. This specification provides a set of WS-Policy assertions for describing the desired security characteristics of web service messages. More specifically it provides the ability for the expression of requirements related to <a title="WSS TC hompage, with links to specs" href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=wss">WSS</a>, <a title="WS-SecureConversation namespace" href="http://docs.oasis-open.org/ws-sx/ws-secureconversation/200512">WS-SecureConversation</a> and <a title="WS-Trust namespace" href="http://docs.oasis-open.org/ws-sx/ws-trust/200512">WS-Trust</a>. This specification has been under development within the <a title="WS-SX TC homepage" href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=ws-sx">OASIS WS-SX TC</a> for over a year now. I&#8217;m happy to say that the <a title="OASIS homepage" href="http://www.oasis-open.org/home/index.php">OASIS</a> member familiarization period for the specification began this month. So what does that mean?</p>
<p>At OASIS a specification must be approved by at least 15% of the membership to become an OASIS standard. When a specification is deemed mature enough by a an OASIS Technical Committee (TC) it is submitted to the OASIS staff. The staff then initiates a member familiarization period on the first of the month after the request is made. The membership has 15 days to become familiar with the specification. On the 15th of the month the specification is placed on a ballot on which the voting representative for each member company at OASIS can cast a vote in favor or opposed to the specification becoming an OASIS standard.</p>
<p>If your company is an OASIS member and you are not familiar with the specification now is the time. Copies of the specification in all of you favorite document formats can be found at the WS-SecurityPolicy namespace location: <a title="WS-SecurityPolicy namespace - RDDL and links to the spec" href="http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702">http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702</a></p>
<p>Will I be back here asking for your vote come the 15th of June? You&#8217;d better believe it.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/06/05/ws-securitypolicy-member-familiarization-has-begun/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Understanding WS-Federation</title>
		<link>http://unverifiedclaims.com/2007/06/04/understanding-ws-federation/</link>
		<comments>http://unverifiedclaims.com/2007/06/04/understanding-ws-federation/#comments</comments>
		<pubDate>Mon, 04 Jun 2007 06:52:28 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[WS-Federation]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/06/04/understanding-ws-federation/</guid>
		<description><![CDATA[Last week&#160;Microsoft and IBM published the&#160;Understanding WS-Federation (html &#124; pdf) white paper.&#160;
As Don has already said the paper covers two scenarios in which different features of WS-Federation are demonstrated. I think the two scenarios chosen provide an accessible introduction to these features. 
The first example covers an enterprise business scenario around an RFP service. This [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://upload.wikimedia.org/wikipedia/commons/2/28/Carte_suisse2.png" atomicselection="true"><img height="221" alt="Switzerland has a Canton with a great name..." src="http://upload.wikimedia.org/wikipedia/commons/2/28/Carte_suisse2.png" width="311" align="left"></a>Last week&nbsp;Microsoft and IBM published the&nbsp;Understanding WS-Federation (<a title="Understanding WS-Federation html" href="http://msdn2.microsoft.com/en-us/library/bb498017.aspx">html</a> | <a title="Understanding WS-Federation pdf" href="http://download.boulder.ibm.com/ibmdl/pub/software/dw/specs/ws-fed/WS-FederationSpec05282007.pdf?S_TACT=105AGX04&amp;S_CMP=LP">pdf</a>) white paper.&nbsp;</p>
<p>As <a title="des on Federated Identity" href="http://identity-des.com/">Don</a> <a title="Don's post on Understanding WS-Federation" href="http://identity-des.com/2007/05/31/understanding-ws-federation/">has already said</a> the paper covers two scenarios in which different features of <a title="WS-Federation specification" href="http://specs.xmlsoap.org/ws/2006/12/federation/">WS-Federation</a> are demonstrated. I think the two scenarios chosen provide an accessible introduction to these features. </p>
<p>The first example covers an enterprise business scenario around an RFP service. This example shows a simpler federation scenario between two participants. The second example is a healthcare scenario around access to patient records. This a more complicated example involving three participants. The paper is not exhaustive in its coverage of the specification but it wasn&#8217;t intended to be. I think we did hit a good balance between breadth and depth. Anyone who reads this paper should&nbsp;come away with a good handle on&nbsp;the capabilities of WS-Federation and how it builds upon WS-Trust.</p>
<p>We&#8217;ll be covering some of this material at the first meeting of the <a title="WSFED TC home page" href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=wsfed">WSFED TC</a> next week, I&#8217;ll provide an update on that here after the meeting.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/06/04/understanding-ws-federation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>This feels&#8230; familiar</title>
		<link>http://unverifiedclaims.com/2007/06/02/this-feels-familiar/</link>
		<comments>http://unverifiedclaims.com/2007/06/02/this-feels-familiar/#comments</comments>
		<pubDate>Sat, 02 Jun 2007 08:29:18 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[recursive]]></category>

		<guid isPermaLink="false">http://unverifiedclaims.com/2007/06/02/this-feels-familiar/</guid>
		<description><![CDATA[Yes, I think I&#8217;ve been here before.
I&#8217;ve even found bits I could recycle to explain myself, I had to change more characters than words to update it. That scares and comforts me.
This place is going to be used for my own musing and linkings to things related to security. That&#8217;s specific and broad enough for [...]]]></description>
			<content:encoded><![CDATA[<p>Yes, I think I&#8217;ve been here before.</p>
<p>I&#8217;ve even <a href="http://unverifiedclaims.com/about/" title="about me">found bits I could recycle to explain myself</a>, I had to change more characters than words to update it. That scares and comforts me.<a atomicselection="true" href="http://en.wikipedia.org/wiki/Ouroboros" title="Ouroboros"><img align="right" src="http://upload.wikimedia.org/wikipedia/commons/thumb/8/87/Ouroboros_1.jpg/300px-Ouroboros_1.jpg" /></a></p>
<p>This place is going to be used for my own musing and linkings to things related to security. That&#8217;s specific and broad enough for now. I expect for most of this too be on identity and web service security related topics, but I&#8217;m sure I&#8217;ll find things within the realm of security that won&#8217;t fit in those buckets to mention as well.</p>
<p>Now&#8230; to get it and keep it going.</p>
]]></content:encoded>
			<wfw:commentRss>http://unverifiedclaims.com/2007/06/02/this-feels-familiar/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
