Interop Capabilities: Service Provider
From OSIS Open Source Identity Systems
Edit History
- 2007.6.06: dr: add VeriSign to the grid
- 2007.5.01: pt: Tweaked a few rows and the Higgins column
- 2007.4.30: pt: worked on the Higgins column
- 2007.3.20: pd: created initial table
- 2007.3.27: pd: added 4 more RP columns & claimed a column for PamelaWare
- 2007.4.03: pd: filled column for PamelaWare, added 'id="pw" | [yes|no]' to help differentiate columns
- 2007.4.12: jb: changed RP D to BMC
- 2007.4.13: jb: entered BMC proposed supported features
- 2007.4.16: mbj: Entered MS Sample column
- 2007.4.17: aj: Filled column for Ping Identity.
- 2007.4.22: cmort: Filled in xmldap
| Relying Party/Service Provider Interop Feature Plan - June 6, 2007 (v5)
| |||||||||
| Feature | MS Sample | PamelaWare | Higgins | BMC | Ping Identity | xmldap.org | Oracle | NetMesh | VeriSign |
| Identity Agent Trigger Mechanism | |||||||||
| HTML Object | yes | yes | yes | yes | yes | yes | yes | yes | no |
| XHTML Object | yes | yes | yes | yes | yes | yes | yes | yes | yes |
| Policy Discovery | |||||||||
| HTML Object | yes | yes | yes | yes | yes | no | |||
| XHTML Object | yes | yes | yes | yes | yes | yes | |||
| RP STS | no | no | no | no | no | ||||
| Accepted Set of Claims | |||||||||
| http://schemas.xmlsoap.org/ws/2005/05/identity/claims | yes | yes | yes | yes | yes | yes | yes | yes | PPID only |
| Other | yes | no | yes | yes | no | yes | no | ||
| Privacy Statement Advertised for IdA pickup | |||||||||
| Via HTML | yes | yes | yes | yes | yes | no | |||
| Via XHTML | yes | yes | yes | yes | yes | yes | |||
| Via RP STS | no | no | no | no | no | no | |||
| Signing & Encryption Accepted | |||||||||
| Accepts tokens signed with 128-bit strength | yes | yes | yes | yes | yes | yes | yes | yes | no |
| Accepts tokens signed with 256-bit strength | yes | yes | yes | yes | |||||
| Accepts/handles EV certificates | yes | yes | need EV certificates | yes | yes | tbd | TBD | yes | |
| Encryption Advertised | |||||||||
| Uses an EV Certificate | yes | yes | yes | yes | TBD | yes | |||
| Uses a standard Certificate | yes | yes | yes | yes | yes | no | |||
| Token Type Accepted | |||||||||
| SAML 1.1 | yes | yes | yes | yes | yes | yes | yes | yes | yes |
| SAML 2.0 | no | no | no | yes | no | TBD | no | ||
| Other Token Type | no | no | yes(idemix) | no | no | ||||
| Validation | |||||||||
| PPID verified as related to IdP's Public Key | yes | yes | yes | no | TBD | yes | |||
| Timestamp verified to be within a validity window | yes | yes | yes | yes | yes | Yes | yes | ||
| Web Server Platform | |||||||||
| Apache | no | yes | tomcat | No | via mod_jk | Tomcat | |||
| IIS | yes | no | no | yes | No | No | |||
| Sun Web Server | no | no | no | No | No | ||||
| Other | no | no | no | Jetty/Tomcat | Any Servlet Container | OC4J | Tomcat, WebSphere | ||
| Web Language | |||||||||
| PHP | no | yes | no | No | no | ||||
| Java | no | no | yes | yes | yes | Yes | Yes | yes | |
| ASP.Net / C# | yes | no | no | No | no | ||||
| C++ | no | no | no | No | no | ||||
| Other | no | no | yes | No | no | ||||
| Support for Other Identity Technologies | |||||||||
| Username/Password | no | yes | no | yes | yes | yes | Yes | No | yes |
| OpenID 1.1 | no | no | TBD | No | Yes | yes | |||
| OpenID 2.0 | no | no | no | No | tbd | yes | |||
| RSS+SSE | no | no | yes | No | No | no | |||
| SAML 2.0 | no | no | no | yes | No | no | |||
| HTML Scraping | no | no | no | No | No | no | |||
| HTML Form Filling | no | no | no | No | No | no | |||
