<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.11.5 (http://www.squarespace.com/) on Fri, 30 Jul 2010 08:51:57 GMT--><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"><title>Identity Rants &amp; Raves</title><subtitle>Identity Rants &amp; Raves</subtitle><id>http://www.shutuplaura.com/journal/</id><link rel="alternate" type="application/xhtml+xml" href="http://www.shutuplaura.com/journal/"/><link rel="self" type="application/atom+xml" href="http://www.shutuplaura.com/journal/atom.xml"/><updated>2010-07-19T20:35:21Z</updated><generator uri="http://www.squarespace.com/" version="Squarespace Site Server v5.11.5 (http://www.squarespace.com/)">Squarespace</generator><entry><title>Shiny ADFS Interop demo</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/7/19/shiny-adfs-interop-demo.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/7/19/shiny-adfs-interop-demo.html"/><author><name>Laura E. Hunter</name></author><published>2010-07-19T20:35:21Z</published><updated>2010-07-19T20:35:21Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>The inimitable Mike Jones and others have posted a demo of an “Identity mash-up” consisting of components of OpenID, ADFS, WIF, and PHP, established by Microsoft, PayPal and Medtronics.</p>  <p><a title="http://blogs.msdn.com/b/interoperability/archive/2010/07/09/identity-mash-up-federation-demo-using-multiple-protocols-openid-and-ws-federation.aspx" href="http://blogs.msdn.com/b/interoperability/archive/2010/07/09/identity-mash-up-federation-demo-using-multiple-protocols-openid-and-ws-federation.aspx">http://blogs.msdn.com/b/interoperability/archive/2010/07/09/identity-mash-up-federation-demo-using-multiple-protocols-openid-and-ws-federation.aspx</a></p>]]></content></entry><entry><title>Microsoft Online Feature Roadmap</title><category term="ADFS"/><category term="Active Directory"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/7/19/microsoft-online-feature-roadmap.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/7/19/microsoft-online-feature-roadmap.html"/><author><name>Laura E. Hunter</name></author><published>2010-07-19T20:27:50Z</published><updated>2010-07-19T20:27:50Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>At the Worldwide Partner Conference, we got to see an official roadmap for current and planned features for Exchange Online, SharePoint Online, and Office Communication Server Online.</p>  <p>Very nice visual breakdown in the ZDNet article here: <a title="http://www.zdnet.com/blog/microsoft/microsoft-shares-officially-its-future-bpos-plans/6857" href="http://www.zdnet.com/blog/microsoft/microsoft-shares-officially-its-future-bpos-plans/6857">http://www.zdnet.com/blog/microsoft/microsoft-shares-officially-its-future-bpos-plans/6857</a></p>]]></content></entry><entry><title>The Windows Azure &amp;ldquo;One-Pager&amp;rdquo;</title><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/6/22/the-windows-azure-ldquoone-pagerrdquo.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/6/22/the-windows-azure-ldquoone-pagerrdquo.html"/><author><name>Laura E. Hunter</name></author><published>2010-06-22T14:59:33Z</published><updated>2010-06-22T14:59:33Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>Of all the articles I’ve seen offering an introduction to cloud computing, I think this one has done the best job thus far:</p>  <p><a title="http://arstechnica.com/microsoft/guides/2010/06/microsoft-azure-for-nubcakes.ars" href="http://arstechnica.com/microsoft/guides/2010/06/microsoft-azure-for-nubcakes.ars">http://arstechnica.com/microsoft/guides/2010/06/microsoft-azure-for-nubcakes.ars</a></p>  <p>Compares and contrasts the various vendor cloud offerings: Azure, EC2, etc., along with the different storage models that each of them use.</p>]]></content></entry><entry><title>ADFS2/Shibboleth interop</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/6/21/adfs2shibboleth-interop.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/6/21/adfs2shibboleth-interop.html"/><author><name>Laura E. Hunter</name></author><published>2010-06-21T19:15:28Z</published><updated>2010-06-21T19:15:28Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>I’ve had a few people ping me lately about setting up ADFS 2.0 to federate with a Shibboleth instance, now that everyone speaks SAML 2.0 and we all get to hold hands and sing Kum-ba-ya in a happy interoperable way.</p>  <p>There are a few “tricks” to make the conversation work well, though, particularly as regards formatting of claims from one org to the other. The ADFS PG has published a walk-through describing a PoC setup <a href="http://blogs.msdn.com/b/card/archive/2010/06/21/a-quick-walkthrough-setting-up-ad-fs-saml-federation-with-a-shibboleth-sp.aspx" target="_blank">here</a>.</p>  <p>Happy federating!</p>]]></content></entry><entry><title>Bouncy Slide with a Twist</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/6/20/bouncy-slide-with-a-twist.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/6/20/bouncy-slide-with-a-twist.html"/><author><name>Laura E. Hunter</name></author><published>2010-06-20T21:25:53Z</published><updated>2010-06-20T21:25:53Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>Matt Steele whiteboards the process of using ADFS to project federated identities to an application hosted in Windows Azure: <a href="http://bit.ly/b6GEYk" target="_blank">http://bit.ly/b6GEYk</a></p>]]></content></entry><entry><title>Creating an ADFS/CA SiteMinder SharePoint SSO lab</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/6/20/creating-an-adfsca-siteminder-sharepoint-sso-lab.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/6/20/creating-an-adfsca-siteminder-sharepoint-sso-lab.html"/><author><name>Laura E. Hunter</name></author><published>2010-06-20T17:53:19Z</published><updated>2010-06-20T17:53:19Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>“Creating a Virtual Organization Using Federated Identity Services with CA SiteMinder and Microsoft Active Directory Federation Services”</p>  <p>White paper (DOCX or PDF) available from the Interop Vendor Alliance <a href="http://interopvendoralliance.org/labs/virtual-organization-using-federated-identity-services.aspx" target="_blank">here</a>.</p>  <p>Happy downloading!</p>]]></content></entry><entry><title>Federation Trust Partner Certificates</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/5/29/federation-trust-partner-certificates.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/5/29/federation-trust-partner-certificates.html"/><author><name>Laura E. Hunter</name></author><published>2010-05-29T15:36:24Z</published><updated>2010-05-29T15:36:24Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p>So we all know that the thing that breaks AD FS is PKI. What’s sometimes frustrating? Is that it’s not always “your problem”.</p>  <p>In a federated trust relationship, an AD FS-protected application will often fail because a certificate on the partner side has expired, often without the partner being aware of it. Which makes for a fun day of trying to track down “the ADFS guy” in the other organization to convince them that they need to go update their (most often) token-signing certificate.</p>  <p>Now, there’s no actual way to prevent this from occurring – you don’t control your partner’s infrastructure, and that’s kinda the point.</p>  <p>But AD FS 2.0 will at least try to alert you that a problem may be about to occur, by logging an event when one of your configured partner’s certificates is about to expire, or has actually expired:</p>  <p><strong>Event ID 389</strong>    <br />AD FS 2.0 detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon.</p>  <p>If AD FS 2.0 is a major part of your operational life, this event needs to trigger an alert in your monitoring system of choice.</p>]]></content></entry><entry><title>Information Card Issuance CTP</title><category term="ADFS"/><category term="Community"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/5/26/information-card-issuance-ctp.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/5/26/information-card-issuance-ctp.html"/><author><name>Laura E. Hunter</name></author><published>2010-05-26T16:26:17Z</published><updated>2010-05-26T16:26:17Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p><a title="https://connect.microsoft.com/site642/content/content.aspx?ContentID=16878" href="https://connect.microsoft.com/site642/content/content.aspx?ContentID=16878">https://connect.microsoft.com/site642/content/content.aspx?ContentID=16878</a></p>  <p>“The Information Card Issuance Community Technology Preview (CTP) Add-On for Active Directory Federation Services 2.0 RTM enables issuance of IMI 1.0- and IMI 1.1-compliant information cards from the released version of AD FS 2.0.</p>  <p>The goal of the CTP is to enable the community to continue to exercise the capabilities of the identity metasystem, as relates specifically to information card issuance, in testing, pilots, and other non-production environments.”</p>  <p>MS “have also adding two new mechanisms for interaction and feedback on this topic, a dedicated Information Card Issuance <a href="http://social.msdn.microsoft.com/Forums/en-US/windowscardspace/threads">Forum</a> and a monitored e-mail alias <a href="mailto:ici-ctp@microsoft.com">ici-ctp@microsoft.com</a>.”</p>]]></content></entry><entry><title>Windows Azure Architecture Guidance</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/5/25/windows-azure-architecture-guidance.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/5/25/windows-azure-architecture-guidance.html"/><author><name>Laura E. Hunter</name></author><published>2010-05-25T21:09:17Z</published><updated>2010-05-25T21:09:17Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p><a title="http://wag.codeplex.com/releases/view/45438" href="http://wag.codeplex.com/releases/view/45438">http://wag.codeplex.com/releases/view/45438</a></p>  <p>Eugenio Pace’s current Patterns &amp; Practices project, Part 1 at least is in Release Candidate stage.</p>]]></content></entry><entry><title>Kim Cameron on Identity, Federation and the Cloud</title><category term="ADFS"/><category term="Identity"/><category term="tech"/><id>http://www.shutuplaura.com/journal/2010/5/25/kim-cameron-on-identity-federation-and-the-cloud.html</id><link rel="alternate" type="text/html" href="http://www.shutuplaura.com/journal/2010/5/25/kim-cameron-on-identity-federation-and-the-cloud.html"/><author><name>Laura E. Hunter</name></author><published>2010-05-25T20:06:06Z</published><updated>2010-05-25T20:06:06Z</updated><content type="html" xml:lang="en-US"><![CDATA[<p><a title="http://www.halbheer.info/security/2010/05/25/identity-in-the-cloud" href="http://www.halbheer.info/security/2010/05/25/identity-in-the-cloud">http://www.halbheer.info/security/2010/05/25/identity-in-the-cloud</a></p>  <p>Presentation, slides and interview. A good listen, as always, from Kim.</p>]]></content></entry></feed>