Test: OASIS Security Services Technical Committee
29-Sep-2005: The individual SAML V2.0 schema files are now available from persistent URLs of the form " http://docs.oasis-open.org/security/saml/v2.0/...". They are all linked from the SAML V2.0 and Post-V2.0 Information section below.
16-Aug-2005: The Liberty Alliance ran a SAML V2.0 interoperability testing session, which was successfully completed by eight companies.
Overview:SAML, developed by the Security Services Technical Committee of OASIS, is an XML-based framework for communicating user authentication, entitlement, and attribute information. As its name suggests, SAML allows business entities to make assertions regarding the identity, attributes, and entitlements of a subject (an entity that is often a human user) to other entities, such as a partner company or another enterprise application.
For more information, see the TC Charter and FAQ
Subcommittees:The SSTC has a SAML Adoption Subcommittee. Technical Work Produced by the Committee:
- SAML Profiles, Bindings, and Extensions
- SAML V2.0 and Post-V2.0 Information
- SAML V1.1 Information
- SAML V1.0 Information
Although not produced by the SSTC, the following information offers useful insights into its work:
- Liberty Alliance ID-FF V1.2 specifications (which were contributed to the SSTC in November 2003)
- MIME media type registrations for application/samlassertion+xml and application/samlmetadata+xml (these registrations were done in coordination with the SAML V2.0 activity)
- Using SAML for SIP Internet draft; describes how to use SAML for trait-based authorization
- SAML entry on Wikipedia
- Security Assertion Markup Language (SAML) Version 1.0 an OASIS Open Standard: XML Cover Pages, 12 Nov 2002
- Security Assertion Markup Language (SAML) Version 1.1 Ratified as OASIS Standard: OASIS News, 22 Sep 2003
- SAML Reference Document: XML Cover Pages, 10 Dec, 2005
- SAML Overview: XML Cover Pages, 10 Mar 2005
- Security Assertion Markup Language (SAML) V2.0 Approved as OASIS Standard: CoverPages, 14 Mar 2005
- Yuri Demchenko's SAML and XACML Overview
security-services: the list used by TC members to conduct Committee work. TC membership is required to post. TC members are automatically subscribed; the public may view archives.
saml-dev: an unmoderated, public mail list that provides an open forum for developers to exchange ideas and information on implementing the SAML OASIS Standard. Subscribe or view archives.*
*To minimize spam, you must subscribe to these lists before posting.
Mail archives are available for the following SSTC mailing lists that are no longer in use.
- security-use
- security- core
- security- protocol
- security- bindings
- security- consider
- security- conform
Past SSTC chairs and co-chairs:
- Joe Pato, Hewlett-Packard and Jeff Hodges, Sun Microsystems (May 2001 to Nov 2002)
- Eve Maler, Sun Microsystems (Jan 2001 to May 2001)
- Marc Chanliau, Netegrity (Jan 2001)
- 4231 reads