<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: zermatt]]></title>
    <link>http://securityratty.com/tag/zermatt</link>
    <description></description>
    <pubDate>Wed, 09 Jul 2008 16:27:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Zermatt is now Geneva Framework]]></title>
      <link>http://securityratty.com/article/ffdbf806596ce2b9eecd4ab50a7394dc</link>
      <guid>http://securityratty.com/article/ffdbf806596ce2b9eecd4ab50a7394dc</guid>
      <description><![CDATA[For those who didn't attend PDC, the Zermatt identity framework has been re-code-named Geneva Framework so that it fits in with the Geneva family of products
Geneva Framework : a .NET class library...]]></description>
      <content:encoded><![CDATA[<p>For those who didn&#39;t attend PDC, the <a href="http://www.pluralsight.com/community/blogs/keith/archive/2008/07/09/introducing-microsoft-code-name-zermatt.aspx">Zermatt identity framework</a> has been re-code-named Geneva Framework so that it fits in with the <a href="http://www.microsoft.com/geneva" target="_blank">Geneva family of products</a>:</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/04/microsoft-geneva-framework.aspx" target="_blank">Geneva Framework</a>: a .NET class library called Microsoft.IdentityModel (basically it&#39;s an updated Zermatt)</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/04/geneva-server-beta.aspx" target="_blank">Geneva Server</a>: This is essentially ADFS v2, built on top of the Geneva Framework</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/18/the-cardspace-geneva-selection-experience.aspx" target="_blank">Geneva CardSpace</a>: This is CardSpace v2.</p>
<p>This link takes you to the &quot;Geneva&quot; landing page at Microsoft, where you&#39;ll find links to all of the bits, as well as the whitepaper v2. The new version of the whitepaper was co-authored by myself and a PM on the Geneva Framework team, Sesha Mani, who added a bunch of new details based on the PDC version of the framework.</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=55244" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 11:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/geneva">geneva</category>
      <category domain="http://securityratty.com/tag/geneva framework">geneva framework</category>
      <category domain="http://securityratty.com/tag/zermatt">zermatt</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <category domain="http://securityratty.com/tag/geneva family">geneva family</category>
      <category domain="http://securityratty.com/tag/zermatt identity framework">zermatt identity framework</category>
      <category domain="http://securityratty.com/tag/geneva cardspace">geneva cardspace</category>
      <category domain="http://securityratty.com/tag/cardspace">cardspace</category>
      <category domain="http://securityratty.com/tag/geneva framework team">geneva framework team</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/11/26/zermatt-is-now-geneva-framework.aspx">Zermatt is now Geneva Framework</source>
    </item>
    <item>
      <title><![CDATA[Zermatt in Community Server]]></title>
      <link>http://securityratty.com/article/e775efcf6afa32aabd54630993695eaa</link>
      <guid>http://securityratty.com/article/e775efcf6afa32aabd54630993695eaa</guid>
      <description><![CDATA[I'm about to embark on a mission to get Zermatt integrated into pluralsight.com as our single-sign-on solution, and a big part of that is getting our Community Server installation wired into that. I'm...]]></description>
      <content:encoded><![CDATA[<p>I&#39;m about to embark on a mission to get Zermatt integrated into pluralsight.com as our single-sign-on solution, and a big part of that is getting our Community Server installation wired into that. I&#39;m curious if anyone else has seen any work being done in this area, or if I&#39;ll be the first?</p> <p>I plan to blog about my progress (and share it) if there&#39;s not already a built-in solution out there.</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=53780" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 18:07:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/built-in solution">built-in solution</category>
      <category domain="http://securityratty.com/tag/single-sign-on solution">single-sign-on solution</category>
      <category domain="http://securityratty.com/tag/zermatt">zermatt</category>
      <category domain="http://securityratty.com/tag/embark">embark</category>
      <category domain="http://securityratty.com/tag/progress">progress</category>
      <category domain="http://securityratty.com/tag/mission">mission</category>
      <category domain="http://securityratty.com/tag/pluralsight">pluralsight</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/curious">curious</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/10/06/zermatt-in-community-server.aspx">Zermatt in Community Server</source>
    </item>
    <item>
      <title><![CDATA[Introducing Microsoft Code Name Zermatt]]></title>
      <link>http://securityratty.com/article/732b3e6ffabbf1bdf556615c13244f16</link>
      <guid>http://securityratty.com/article/732b3e6ffabbf1bdf556615c13244f16</guid>
      <description><![CDATA[For a couple of years now, I've been giving talks about &quot;claims-based identity&quot;, and &quot;claims-aware applications&quot;. The most concrete example of a claims-based identity architecture that I've been able...]]></description>
      <content:encoded><![CDATA[<p>For a couple of years now, I&#39;ve been giving talks about &quot;claims-based identity&quot;, and &quot;claims-aware applications&quot;. The most concrete example of a claims-based identity architecture that I&#39;ve been able to show so far is Active Directory Federation Services v1 (ADFS) and Windows CardSpace. And the claims programming model I&#39;ve been using is the one that shipped with WCF in the System.IdentityModel assembly.<br /><br />But today I&#39;m happy to announce that there&#39;s a new path forward in the claims world. <a href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=642&amp;DownloadID=12937">Zermatt</a> is the &quot;identity framework&quot; that I&#39;ve been itching to talk about, but until today, hasn&#39;t been announced publicly.<br /><br />Well, <a href="http://blogs.msdn.com/vbertocci/">Vittorio</a> just made the <a href="http://blogs.msdn.com/vbertocci/archive/2008/07/09/announcing-the-beta-release-of-zermatt-developer-identity-framework.aspx">announcement</a> just a moment ago, and now you can get your hands on this new framework. With it, you can build web applications and services that rely on claims to discover identity details about users. And you can easily build a security token service (STS) that supplies those claims. Zermatt makes this possible by supplying all of the plumbing that implements WS-Trust (for web services) and WS-Federation (for browser-based web applications). All you have to do is figure out what claims you want to issue based on what you know about the user and what you know about the application (aka relying party).<br /><br />I was fortunate to be asked by the team to write the <a href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=642&amp;DownloadID=12901">white paper</a> introducing Zermatt to developers. You can download it here. The paper introduces the ideas behind claims-based identity, and talks about how you can use Zermatt to centralize authentication (and to some degree, authorization) in an STS, thus making it easy to achieve single sign on in your applications, and even be ready to federate with other organizations or platforms should that need arise.<br /><br />Here are some highlights of what you&#39;ll find in Zermatt:<br /><br />Zermatt includes a new claims programming model, with IClaimsPrincipal and IClaimsIdentity, two new interfaces that extend the existing IPrincipal and IIdentity that you already know and love from the .NET Framework. IClaimsIdentity adds a collection of claims. Zermatt&#39;s claims programming model is in many ways simpler than that in WCF - the Claim class exposes the value of claims as strings (always) and calls the value of a claim &quot;Value&quot;, instead of &quot;Resource&quot; as WCF did. But the model is also more sophisticated - multi-hop delegation is supported, so one user can &quot;Act As&quot; another user, and the relying party will see the entire chain of delegation as a linked list of IClaimsIdentity objects.<br /><br />Zermatt includes an HttpModule that you can wire into your ASP.NET application that will implement WS-Federation for you. This module (called the FAM) is a lot like the &quot;Web Agent&quot; from ADFS, and it makes it quite easy to build a web application that relies on claims.<br /><br />Zermatt includes plumbing that sits on top of WCF and simplifies building claims-based web services and clients.<br /><br />Zermatt also includes a couple of ASP.NET controls for adding SignIn functionality to websites. The first is a passive sign-in control which simply redirects the browser to an STS to get claims. The second is the highly anticipated InformationCard control that pops the user&#39;s identity selector and lets her choose which identity she wants to use.<br /><br />Zermatt comes with a bunch of sample code to help you get started.<br /><br />All you need to test-drive Zermatt is Visual Studio 2008 and your curiosity. Download the beta now, read the whitepaper, experiment with the samples, and see what claims-based identity is all about!<br /><br />For more on Zermatt, you&#39;ll want to watch <a href="http://blogs.msdn.com/vbertocci/">Vittorio&#39;s blog</a>. I&#39;ll also be talking more about it in the future!</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=51689" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 16:27:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zermatt">zermatt</category>
      <category domain="http://securityratty.com/tag/claims world">claims world</category>
      <category domain="http://securityratty.com/tag/claims">claims</category>
      <category domain="http://securityratty.com/tag/zermatt includes">zermatt includes</category>
      <category domain="http://securityratty.com/tag/includes">includes</category>
      <category domain="http://securityratty.com/tag/claims-aware applications">claims-aware applications</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <category domain="http://securityratty.com/tag/identity framework">identity framework</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/07/09/introducing-microsoft-code-name-zermatt.aspx">Introducing Microsoft Code Name Zermatt</source>
    </item>
  </channel>
</rss>
