News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 
Download Current Issue
ISSUE 3/15/2010 PDF

Need Back Issues?
DOWNLOAD HERE

Receive the print Edition?


 
blogs tab
Google Code turns 5
Google Code Turns 5, and adds a Paxos Algorithm to make the system more stable and reliable.
03/17/2010 11:16 AM EST

Test your Visual Studio 2010 know-how
Microsoft is offering free beta certification exams for Visual Studio 2010.
03/17/2010 11:08 AM EST

Microsoft lifts the hood on IE9
Microsoft is previewing IE9.
03/16/2010 01:10 PM EST

 

Events calendar tab
3/22/2010 to 3/25/2010
Santa Clara, Calif.
The Eclipse Foundation

4/12/2010 to 4/14/2010
Las Vegas
Penton Media

4/12/2010 to 4/15/2010
Santa Clara, Calif.
O'Reilly Media

4/19/2010
New York City
Flagg Management

4/25/2010 to 4/28/2010
Overland Park, Kans.
IIUG


 
Most Read Latest News Blog Resources

Open-source identity scheme takes first steps




March 13, 2008 — 
Concerned that the Web 2.0 craze is catching on faster than security can catch up, the OpenLiberty.org community has released an open source code library to write Web applications that protect users’ identities and increase security.

A beta version of OpenLiberty-J, released March 10, enables application developers to incorporate into their software the enterprise-grade interoperability, security and privacy capabilities of the Liberty Alliance’s Java library for identity Web services. OpenLiberty can be used for enterprise applications in service-oriented architectures, social network environments and other client-side applications for PCs and mobile devices.

Although the Web is popular, it’s immature, especially as it relates to security and privacy, claimed Brett McDowell, executive director of the Liberty Alliance, sponsor of the OpenLiberty.org community.

“We are bringing those high-quality features, previously only available to the enterprise, to the long tail of the Internet and everyone who's interested in this Web 2.0 phenomenon,” said McDowell.

Currently available security and privacy schemes have their drawbacks, he continued. Some earlier Web applications create “identity silos,” in which each application or site has its own identity management protocol and a user has to use a different scheme for each site they use. “This is the old-school way of doing it.”

The other alternative is some kind of “global identifier,” which someone could use to establish their identity at multiple sites, McDowell noted, but added that global identifier technology is still new and presents its own security concerns.

A core technology in the OpenLiberty-J framework is Security Assertion Markup Language (SAML) 2.0, which he described as the de facto standard for exchanging authentication and authorization data online. The open-source version is called OpenSAML.

“We have years of complexity in here,” McDowell said of OpenLiberty-J. “We have done the hard work of putting all those features into your library, and you [can go ahead and] build your applications.”

Although this OpenLiberty release is limited to developing Java-based applications, McDowell said the Alliance plans to eventually port the library to .NET, PHP, Ruby and other platforms.

OpenLiberty-J is also based on Java SE, open-source XML and  service libraries from the Apache Software Foundation and the Internet2 Shibboleth project, which is responsible for OpenSAML.


Related Search Term(s): OpenLibertyLiberty Allianceopen sourceWeb 2.0


Share this link: http://www.sdtimes.com/link/31835
 

Add comment


Name*
Email*  
Country     


  • Comment
  • Preview
Loading