Thursday, February 26, 2009

Public Review of Identity Metasystem Interoperability Version 1.0

OASIS has sent the following information out today:

The OASIS Identity Metasystem Interoperability TC has recently approved the following specification as a Committee Draft and approved the package for public review:

Identity Metasystem Interoperability Version 1.0

Introduction:
The Identity Metasystem Interoperability specification prescribes a subset of the mechanisms defined in WS-Trust 1.2, WS-Trust 1.3, WS-SecurityPolicy 1.1, WS-SecurityPolicy 1.2, and WS-MetadataExchange to facilitate the integration of Digital Identity into an interoperable token issuance and consumption framework using the Information Card Model. It documents the Web interfaces utilized by browsers and Web applications that utilize the Information Card Model. Finally, it extends WS-Addressing's endpoint reference by providing identity information about the endpoint that can be verified through a variety of security means, such as https or the wealth of WS-Security specifications.

This profile constrains the schema elements/extensions used by the Information Card Model, and behaviors for conforming Relying Parties, Identity Providers, and Identity Selectors.

The public review starts today, 26 February 2009, and ends 27 April 2009. This is an open invitation to comment. We strongly encourage feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of OASIS work. Please feel free to distribute this announcement within your organization and to other appropriate mail lists.

More non-normative information about the specification and the technical committee may be found at the public home page of the TC at http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=imi. Comments may be submitted to the TC by any person through the use of the OASIS TC Comment Facility which can be located via the button marked "Send A Comment" at the top of that page, or directly at http://www.oasis-open.org/committees/comments/index.php?wg_abbrev=imi.

Submitted comments (for this work as well as other works of that TC) are publicly archived and can be viewed at http://lists.oasis-open.org/archives/imi-comment/. All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the
feedback you provide carries the same obligations at least as the obligations of the TC members.

The specification document and related files are available here:

Editable Source:
http://docs.oasis-open.org/imi/identity/v1.0/cd/identity-1.0-spec-cd-02.doc

PDF:
http://docs.oasis-open.org/imi/identity/v1.0/cd/identity-1.0-spec-cd-02.pdf

HTML:
http://docs.oasis-open.org/imi/identity/v1.0/cd/identity-1.0-spec-cd-02.html


Schema:
http://docs.oasis-open.org/imi/identity/v1.0/cd/identity-1.0-cd-02.xsd
http://docs.oasis-open.org/imi/identity/v1.0/cd/addr-identity-1.0-cd-02.xsd
http://docs.oasis-open.org/imi/identity/v1.0/cd/claims-1.0-cd-02.xsd

OASIS and the IMI TC welcome your comments.


I hope that we will have an official OASIS standard for Information Cards soon.
Well, musing about "soon". I am wondering how long these things take. I joined Chuck Mortimore and the Openinfocard project in August 2006. We had the first open source Information Card relying party and the first open source IdP, both written in Java and Java Server Pages. Then of course the first open source card selector as an Firefox extension, written in javascript, XUL and Java.
Time is flying when you are having fun.

Wednesday, February 04, 2009

java 6 update 12 for openinfocard


Java 6 update 12 has been released. Please install this update because it contains a fix (6745455) especially for Firefox extensions that use java like the openinfocard id selector. openinfocard users on MacOS still have to disable the plugin2 and use the dying OJI plugin (or stay with Firefox 2...); although that is not really satisfying... I hope that Apple will leap ahead soon from java 1.6u7 to 1.6u12.

Thank you SUN for fixing this.

Sunday, January 25, 2009

Backward Compatibility. Java, Mozilla, Sun, IBM, Microsoft

About a week ago there were press articles about SAP paying SUN Microsystem to support SAP customers with stoneage java 1.4 users/systems.

Unfortunately there is nobody who wants to own and support the stoneage OJI project that puts java support into Firefox. The new way to support java is provided through the NSAPI plugin interface and the new thing is called "plugin2". Unfortunately (again) SUN forgot - or never knew - that Firefox extensions have - if they want - all the rights of the Firefox user. SUN implemented plugin2 having java applets in mind. Firefox extension that use java were forgotten.

But Sun is very helpful to ease the pain and supports me - thanks Kenneth - in rewriting the java classloading stuff from OJI to plugin2. But (again) you need java 6 update 12 or newer for this to work. This version of java has a patch for plugin2 that gives Firefox extensions the necessary priveledges.

So currently there are two options for openinfocard users: either disable plugin2 as I discribed in previous posts or install java6u12ea.
When Mozilla stops support for OJI then there is only the option to install a current version of java. I guess that Firefox 3.2 will not have OJI inside.

This reminds of an email thread/t on the higgins-dev mailing list. Where most developers wished for java 5 in higgins but IBM's shogun ordered his men to commit harakiri should they become traitors to java 1.4. Well, I am exaggerating...

I guess that IBM does not want to pay SU... - Hm, IBM has its own java - IBM to migrate customers stoneage IBM systems to a better world?!

Other memories bubble up: Did you remember the news that Microsoft CardSpace was downgraded to run on FAT file systems?

Well, well, well. I am happy that openinfocard is provided AS-IS.
I will do my best to support all versions of Firefox on all platforms, but my resources are limited. So we all should be happy if we can always work with the latest and greatest software. Happy downloading. Enjoy.

3500 New Jobs at Deutsche Telekom

Today I read about SUN Microsystem laying off 1500 people. Last week I read about Microsoft laying off 5000 people.
Time for some good news: Deutsche Telekom says it might offer 3500 new jobs.

Deutsche Telekom is planning up to 3,500 new jobs in Germany in 2009, dependent on the economic development in its individual business segments, CHRO Thomas Sattelberger announced today in Bonn.

Wednesday, January 21, 2009

SUN ONLINE ACCOUNT Identity Management Stinks

I am currently testing the openinfocard identity selector with Firefox 3.1 beta 2.
Well, this does not look good.

The color/layout of the xmldap relyingparty is "different" to the Firefox 3.0.5 look.
The fonts look strange.
The layout of the claims in the openinfocard CardManager window is completely disastrous.
The generation of self-issued security tokens through Java does not work. No error message - just nothing happening. This is what I like.

wrong layout and wrong colors and rotten fonts

As a good member of the Sun / Mozilla developer community I searched SUN's bug database for something related.
The bug (6745455) "Firefox extensions using Java don't work with new Java Plug-In" looks interesting. BUT you need an account to see this! What is this? Still quite cool at this point. So I tried my SunSolve account to login but the contract seems to be expired. Next I tried my SUN Developer Network account but still no access to this bug. Well SUN Online is offering me to register for a SUN ONLINE ACCOUNT. Pseudonyms are cheap. Tried this, verified my email address, relogin, BUT still no access to this bug.
This stinks!
Now I have three SUN accounts. The first two because years ago SUN was not able to merge the two and after SUN forced me to create the second after they tried to consolidate their user databases (but failed). What's more: I can not find the button/link to terminate/delete the new account. Super.

So much for that. I will pester my SUN contact with the java plugin2 error now.
Thank you SUN for wasting my time.

The bug:
if you enter
"Components.classes["@mozilla.org/oji/jvm-mgr;1"].getService(Components.interfaces.nsIJVMManager)"
into the command line of the Firefox console then Firefox 3.0.5 returns
"[xpconnect wrapped nsIJVMManager]" while Firefox 3.1 beta 2 returns "Fehler: Component returned failure code: 0x80570018 (NS_ERROR_XPC_BAD_IID) [nsIJSCID.getService]
Quelldatei: javascript:%20Components.classes["@mozilla.org/oji/jvm-mgr;1"].getService(Components.interfaces.nsIJVMManager)
Zeile: 1"
. My guess is that this is an easy test for the bug that causes openinfocard to stop working with FF3.1b2. Maybe this is easy to fix in the openinfocard extension. I guess that OJI support is dying, but what is the new call to get the Java console?

Tuesday, January 20, 2009

openinfocard codeswarm

A codeswarm video of code repository checkins for the openinfocard project.

Interessting for me are the times of much activity and the times of little activity. Maybe I can provide subtitles like "OSIS Barcelona Interop". I guess that those events triggered many code changes. This is probably a good chance to remind everybody to start testing for the next interop which ends at RSA 2009.

If you want to create your own codeswarm video, it is easy. The repository must understand SVN but that is probably the major obstacle some project might face.

DIDW 2009

This is the first reference to this year's Digital ID World:

I could not find it on CSO's website. The link there currently points to the 2008 event. Does somebody know more or is it cancelled?

To see the full epic movie from which I captured the picture please visit Ping Identity's blog.

Saturday, January 17, 2009

Frightening? Geolocation

Two years ago I was working on VoIP emergency calls and how to determine the location of the caller. With VoIP the problem is equal to determine the location of an IP connected device. The security and privacy issues with this are "tricky".
Last week I played with the new W3C geolocation API draft and Mozilla's GEODE Firefox extension.

Today I restarted my "playground"-laptop and Firefox was restarted and Aza Raskin's geolocation demo site was displayed. I was baffled that the location displayed was my old(!) home address. But then I thought: "Somebody connected my WLAN-router to my old address" and that is why this location gets displayed. Now, three hours later, I wanted to power-off the laptop but reloaded the demo site. INTERESTINGLY, now my new and correct address is displayed. That is frightening. I am now living outside Berlin "in the woods" between Berlin and Potsam but nevertheless there is a connection between my WLAN or my neighbors WLAN to this location. I am not sure whether I want my location resolved by a server in ... whereever. Well, I don't have to use the GEODE extension and the loki.dll that is used by GEODE. Do I trust Skyhook who build loki? Hm, although my G1 and the iPhone too might use WLAN-location but I prefer GPS. With GPS my WLAN environment is not send around the world.

Nevertheless I might write a geolocation provider for Firefox 3.1 which has W3C geolocation support build-in. Maybe that extension (IdP) will use geolocation Information Cards to choose which claims (exact-location, neighborhood, city, ...) to reveal to the RP.

Thursday, January 15, 2009

Playing Around with Microsoft Tags

Some see visual tags as a danger to NFC's breakthrough... Well, maybe; but only for a subset of NFC use cases.

Reason enough to try it out. So I created a tag at Microsoft. Had to login with liveid/password. Wondering when Information Card support will be there at liveid... And here it is:

Now we need the software from gettag.mobi. Hmm. Android not available yet for my G1. Symbian S60 is there but my S60 phones (E60 and E61) don't have a camera. My 6131-NFC (well) has a camera. I downloaded the j2me-unlocked program and installed it on the 6131 using Nokia's PC Suite's application installer. I was able to start the tagreader application and it successfuly decoded the tag on this page... but the phone has not valid internet connection settings...

Hm. Enough playing around. I might try it again when an Android G1 tagreader is available.

BTW: the tag points to the openinfocard download area. Well, to be more exact: it points to a Microsoft server that points to the openinfocard download area. So Microsoft is a man-in-the-middle. Do I want that? No.

Thursday, January 08, 2009

openinfocard is now on addons.mozilla.org

I uploaded the current version of the openinfocard firefox extension to addons.mozilla.org. It is there in the experimental section. Sorry you have to have a mozilla account to download it from there. The future current versions will be available at the project's code repository as long as the extension is not in the section of released extensions.

Enjoy.

Tuesday, December 30, 2008

Firefox XRD Extension II

I just uploaded a new version of the XRDS extension for Firefox and a version of the openinfocard extension that uses it.

When the extension xrds_pageinfo.xpi is installed then the openinfocard extension shows the list of cards that where used at this site. Hm, to be more precise: The list of Information Cards is shown of which a record of usage is stored in the cardstore. If you use the new "delete privacy data" feature of the openinfocard extension then no card usage is shown.





Also available in other languages than German.
have fun
Axel

Friday, December 05, 2008

Firefox XRD Extension

Even so progress is slow sometimes...
Sometimes things actually move forward.
Based on the discussion at IIW and the former posts I started to write an extension for Firefox that allows users to see the XRDS provided by a site.

I see this as a further step to get IDentity In the Browser. But not only "openid in the browser" but much more.
First let's see how this looks.

 

Even if you have this new "xrds_pageinfo.xpi" extension installed and visit a site that provides xrds then there is at first not much to see. The site's XRDS is not visible to the user. And that is good as it is. The normal user is not interested in some xml file. The services described in the file matter.

Well. All my new Firefox extension currently does for the user is to show just that xml. Click on the favicon of the site and you will see something like this:

 


But there is more to come and there is more under the hood. The extension implements a component in javascript that allows other extensions to access the discovered XRDS and add/remove handler for services defined in the XRDS.

The current interface definition for the component is:
[function, scriptable, uuid(13e630b8-3f41-456b-ae26-c30b201c8f99)]
interface IXrdsServiceHandler : nsISupports
{
        boolean handle(in nsIDOMElement service, in nsIDOMDocument doc);
};
           
[scriptable, uuid(DDD9BC02-D964-4bd5-B5BC-943E483C6C57)]
interface IXrdsComponent : nsISupports
{
  void addServiceHandler(in ACString xrdsServiceType, in IXrdsServiceHandler aXrdsServiceHandler);
  void removeServiceHandler(in ACString xrdsServiceType, in IXrdsServiceHandler aXrdsServiceHandler);
  
  IXrdsServiceHandler iterator(in ACString xrdsServiceType);
  long getHandlerCount(in ACString xrdsServiceType);
  IXrdsServiceHandler getHandlerByIndex(in ACString xrdsServiceType, in long index);

  void addXrdsForSite(in ACString site, in AUTF8String xrds);
  AUTF8String getXrdsForSite(in ACString site);
};


This interface definition will change. But after I have integrated this into the openinfocard identity selector and after feedback from the other XRD-enthusiasts and perhaps integration into "openid in the browser" I expect something stable no so far away.

What next?
  • provide some useful GUI
    • it should be possible to click on a button and this will retrieve the privacy policy of the relying party or openid consumer if that service is defined by the XRDS.
    • click and the Information Card selector starts and your chosen claims will be send to the RP.
    • click and your openid attributes are retrieved and provided (without stealable credentials being involved).
    • click and the browser opens the page where you can edit your data.
    • click and the browser opens the page that lets you terminate the relation to this site.
    • click and you can present your voucher.
    • click and you are a new customer with verified claims.
  • integrate with openinfocard id selector
  • integrate with IDIB
  • standardize all this
    • standardize service types
    • standardize this usage of XRDS for relying parties, openid consumers, webshops, whatever
    • There are many open questions. Implementing this and defining service types etc is fruitless if there is no (industry) standard.

I hope that I can work in the OASIS TC(s) relevant to this. Currently it looks like joining is next to impossible. I spare you the details.

I would like to end with something positive... So please find the Firefox extension here. Please send suggestions to
Happy Xrd-ing. -Axel

Tuesday, December 02, 2008

Pamela Dingle Speaks

Join veteran Experts Conference speaker Pam Dingle as she shares tips and tricks on how to achieve 'enlightened bottom-up' Identity Management. Pam believes that, as long as you start with a few simple overarching strategic principles, identity management can be 90% tactical. Pamela will use her professional IdM experience to show how the right selection of point solutions in the enterprise can make a world of difference, providing strategic agility to the business while pre-emptively reducing complexity for the future. Look for ILM, Federation and CardSpace to be key technology players in this talk, complete with real-life examples that tie it all together.

The Experts Conference, March 22-25, 2009 in Las Vegas, NV presents her talk "The Survivalists Guide to Identity Management".

Tuesday, November 25, 2008

java again


I got a new computer and tried the openinfocard id selector with it; but Boom the Java code did not run. Hm, I forgot to install a new version. Preinstalled was some Java 1.4 version... I installed Java 1.6 update 10 and tried again, but again it failed. Ahh, the new java plugin for Firefox hit me again.
Error calling method on NPObject! [plugin exception: java.security.AccessControlException: access denied (java.security.SecurityPermission getPolicy)]

I had to set HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.6.0_10\UseNewJavaPlugin from 1 to 0 to disable the new plugin.

After that the openinfocard selector worked again.

Sun promised to fix this in Java 1.6 update 12 but there is no early access version available...
Another bug in the new plugin is that it does not implement the instanceof operator for Java objects.

Kenneth from Sun suggested a workaround: Have to change
if (!(bootstrapClassLoader instanceof java.net.URLClassLoader)) {
to
if (!(bootstrapClassLoader.getClass().isInstance(java.lang.Class.forName("java.net.URLClassLoader")))) {

For this bug there is not even a promise to fix it... Well, thank you SUN for making my life interesting; NOT.

Friday, November 21, 2008

Information Cards for Google Apps

Information Cards are an industry standard that enable people to maintain a set of personal digital identities.
Information Cards are like cards in your wallet. Each one defines a relationship between you -the cardholder- and the card issuer -the identity provider. They provide a way to transfer claims/attributes from the identity provider to a relyingparty. Information Card selectors are available for all major operating systems and major browsers. To learn more about Information Cards please visit the Information Card Foundation.

Having provided support for "SAML Single Sign-On (SSO) Service for Google Apps" not so long ago Google is now proud to present support for Information Cards for Google Apps.
The step from "SAML Single Sign-On (SSO) Service for Google Apps" to Information Card support is actually quite small. This is due to the fact that all Information Card selectors are token agnostic that is: They don't care which type of token is transfered from the identity provider to the relying party. Therefore we choose to use SAML assertions that are used in "SAML Single Sign-On (SSO) Service for Google Apps" too.

Security Assertion Markup Language (SAML) is an XML standard that allows secure web domains to exchange user authentication and authorization data. Using SAML, an online service provider can contact a separate online identity provider to authenticate users who are trying to access secure content.

Google Apps offers an Information Card based claims transfer that provides partner companies with full control over the authorization and authentication of hosted user accounts that can access web-based applications like Gmail or Google Calendar. Using the Information Card model, Google acts as the relying party and provides services such as Gmail and Start Pages. Google partners act as identity providers and control credentials and other information (claims/attributes) used to identify, authenticate and authorize users for web applications that Google hosts. Google wants to point out that it is hard to overestimate the security gains for our partners. By using the authentication methods implemented in e.g. Windows Cardspace partners can use Kerberos, X509 and self-issued cards to authenticate the user to the security token server; thereby leveraging existing corporate infrastructure to access Google Apps through this new services.

There are a number of existing open source and commercial identity provider solutions that can help you implement Information Cards with Google Apps.
It is important to note that the SSO solution only applies to web applications. If you want to enable your users to access Google services with desktop clients such as Outlook—for example, Outlook would provide POP access to Gmail—you will still need to provide your users with usable passwords and synchronize those passwords with your internal user database using the Provisioning API.

The Google Apps with Information Card is based the "Identity Selector Interoperability Profile V1.5". Information Cards are supported by several widely known vendors. Visit the Information Card Foundation to learn more.

Understanding Information Card based usage of Google Apps


The following process explains how a user logs into a hosted Google application through a partner-operated identity provider service.

Figure 1: Logging in to Google Apps using Information Cards


This image illustrates the following steps.
  1. The user attemps to reach a hosted Google application, such as Gmail, Start Pages, or another Google service.
    Google presents a page with the purple-i that denotes that Information Cards can be used here. The RelayState parameter containing the encoded URL of the Google application that the user is trying to reach is transferred to the Google ACS as a form parameter. This RelayState parameter not transferred to the partner. Each google app requests at least one claim that is identitcal to the applications base url e.g. "http://calendar.parityapps.com/".
  2. The user clicks the purple-i icon
  3. The cardselector starts and the user selects her information card e.g. the managed card issued by Parity. The card selectore sends the security token request to the partner
  4. The partner parses the request and authenticats the user using one of the supported authentication methods Kerberos, X509 certificate, self-issued card or username and password
  5. Partner generates SAML assertion (security token).
  6. The browser posts the security token and the other form element's values to the Google ACS
  7. Google's ACS verifies the SAML response using the partner's public key. If the response is successfully verified, ACS redirects the user to the destination URL.
  8. The user has been redirected to the destination URL and is logged in to Google Apps.


^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
I hope to read an anouncement like the fake one above by Google soon ;-)

Tuesday, November 18, 2008

Internet Explorer Mobile 6 Geneva? Not!


Microsoft just announced the new version of Internet Explorer Mobile 6.
The feedback on the PIE blog sounds mostly disappointed.

I guess that the new version still neither has CardSpace support.
I would welcome a mobileCardSpace even if it would have no self-issued card support.
Or maybe we should make the PKCS#5 algorithm in ISIP optional? Self-issued cards are the main reason we don't have mobile selectors.

Sad.

No XHTML at Information Card Tile Page

Is it only me who finds it anoying that Microsoft over and over again produces example pages that have very very illegal (X)HTML code?

The example page for the Information Card Tile has yet several errors that occure when one uses a framework to create HTML pages that simply does not work well.
One should think that Microsoft's programmers have access to tools that produce valid code?! Or maybe all the Micorsoft tools and frameworks are so that they produce invalid code when you include one page into another?

Bad example. Although I like the Information Card Tile. Even though I would implement it in another way. Some time ago I came up with the same idea but did not implement it because that would have been "not standard". Well, now it seems we witness the birth of a new standard.

I would implement the Information Card Tile รก la microformats by using the class attribute. I would add a special class to the HTML-image tag to denote a tile.

If the RP does not want a tile when no selector is installed then:
Example: <image class="InformationCardTile" src="" id="the-ppid" alt="invisible"/>

If the RP does want an image when no selector is installed then:
Example: <image class="InformationCardTile" src="http://rp/image.png" id="the-ppid" alt="Purple Information Card Icon" onclick="submitForm()"/>

The selector would then overwrite the src-attribute when the card with the PPID "the-ppid" exists and add an onclick-handler that starts the selector or sends the card if the user has chosen to always use this card.

Thursday, November 13, 2008

Equifax Unveils Online Identity Card

ATLANTA, November 13, 2008 - Equifax Inc. (NYSE: EFX) unveiled today the Equifax online identity card or I-Card, with a beta test of a first-of-its-kind digital identity management solution that is designed to make online transactions easier and more secure for both consumers and businesses....

Read the whole story at Parity's website.

Wednesday, November 12, 2008

IIW2008b: XRDS for OpenID and Information Cards

We will have a session this morning about XRDS and OpenId and Information Cards.

The IIW2008b wiki has an initial page about this topic.


Please come and let us define something useful.

Sunday, November 09, 2008

"Big Dog" Wow!

Amazing!





Visit Boston Dynamics for the full story.