<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My GlueCon Talk on &#8220;Federated Provisioning and the Cloud&#8221;</title>
	<atom:link href="http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 01 Sep 2011 20:45:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: GLUE Conference &#8211; Gluecon speaker slides</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-300</link>
		<dc:creator>GLUE Conference &#8211; Gluecon speaker slides</dc:creator>
		<pubDate>Sat, 12 Feb 2011 21:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-300</guid>
		<description>[...] Messina on XAuth Aaron Fulkerson - Web Oriented Architecture Jon Meredith - Riak in Ten Minutes Nishant Kaushik - Federated Provisioning and the Cloud Jeff Lindsay on Webhooks Jeff Lawson - Hacking Cloud Communications Monica Keller - Building [...]</description>
		<content:encoded><![CDATA[<p>[...] Messina on XAuth Aaron Fulkerson &#8211; Web Oriented Architecture Jon Meredith &#8211; Riak in Ten Minutes Nishant Kaushik &#8211; Federated Provisioning and the Cloud Jeff Lindsay on Webhooks Jeff Lawson &#8211; Hacking Cloud Communications Monica Keller &#8211; Building [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tatsuo Kudo</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-340</link>
		<dc:creator>Tatsuo Kudo</dc:creator>
		<pubDate>Wed, 09 Jun 2010 07:23:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-340</guid>
		<description>+1 on deprovisioning.  I&#039;m wondering how the enterprise IdP can terminate or disable accounts in the RPs while the target users are offline.</description>
		<content:encoded><![CDATA[<p>+1 on deprovisioning.  I&#39;m wondering how the enterprise IdP can terminate or disable accounts in the RPs while the target users are offline.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tatsuo Kudo</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-241</link>
		<dc:creator>Tatsuo Kudo</dc:creator>
		<pubDate>Wed, 09 Jun 2010 00:23:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-241</guid>
		<description>+1 on deprovisioning.  I&#039;m wondering how the enterprise IdP can terminate or disable accounts in the RPs while the target users are offline.</description>
		<content:encoded><![CDATA[<p>+1 on deprovisioning.  I&#39;m wondering how the enterprise IdP can terminate or disable accounts in the RPs while the target users are offline.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How do you capitalize the &#8220;P&#8221; in federated provisioning &#8211; or &#8211; The Black Knight Always Triumphs</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-232</link>
		<dc:creator>How do you capitalize the &#8220;P&#8221; in federated provisioning &#8211; or &#8211; The Black Knight Always Triumphs</dc:creator>
		<pubDate>Thu, 03 Jun 2010 17:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-232</guid>
		<description>[...] week, Oracle&#8217;s Nishant Kaushik compressed a lot of thought into a very short presentation on federated provisioning and the cloud. Not only did he summarize challenges of federated provisioning, he also proposed 3 alternatives to [...]</description>
		<content:encoded><![CDATA[<p>[...] week, Oracle&#8217;s Nishant Kaushik compressed a lot of thought into a very short presentation on federated provisioning and the cloud. Not only did he summarize challenges of federated provisioning, he also proposed 3 alternatives to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mat Hamlin</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-230</link>
		<dc:creator>Mat Hamlin</dc:creator>
		<pubDate>Wed, 02 Jun 2010 18:04:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-230</guid>
		<description>As usual, great work describing and explaining the concepts and existing limitations around Federated Provisioning.&lt;br&gt;&lt;br&gt;I&#039;m interested to hear your follow on thoughts around how to solve the &quot;missing pieces&quot; problems.  For the missing attributes, I like your #3 suggestion in the slides (OAuth + ArisID) since it does roundtrip all parties and allows for compliant attribute retrieval.  The questions that should be answered are: &lt;br&gt;&lt;br&gt;What attributes are required to provision an account (or role or entitlement) on the cloud based application? (CARML)&lt;br&gt;Where are those attributes sourced from? (identity sources and/or actual people)&lt;br&gt;How is the sourcing and use of attribute data authorized? (IAS, OAuth?)&lt;br&gt;&lt;br&gt;In the enterprise provisioning realm, to answer these questions you could create a &quot;provisioning policy&quot;, which defines per application how the attributes values are sourced?  Do they come from the requestor, the application administrator, or are they mapped / calculated from known identity information?  This becomes difficult in a cross domain scenario and will require the use of standards, as you suggest.&lt;br&gt;&lt;br&gt;I&#039;m also interested in your thoughts on deprovisioning, metering, and closing the audit and control loop with the enterprise-side Identity GRC system.&lt;br&gt;&lt;br&gt;Cheers,&lt;br&gt;&lt;br&gt;Mat Hamlin</description>
		<content:encoded><![CDATA[<p>As usual, great work describing and explaining the concepts and existing limitations around Federated Provisioning.</p>
<p>I&#39;m interested to hear your follow on thoughts around how to solve the &#8220;missing pieces&#8221; problems.  For the missing attributes, I like your #3 suggestion in the slides (OAuth + ArisID) since it does roundtrip all parties and allows for compliant attribute retrieval.  The questions that should be answered are: </p>
<p>What attributes are required to provision an account (or role or entitlement) on the cloud based application? (CARML)<br />Where are those attributes sourced from? (identity sources and/or actual people)<br />How is the sourcing and use of attribute data authorized? (IAS, OAuth?)</p>
<p>In the enterprise provisioning realm, to answer these questions you could create a &#8220;provisioning policy&#8221;, which defines per application how the attributes values are sourced?  Do they come from the requestor, the application administrator, or are they mapped / calculated from known identity information?  This becomes difficult in a cross domain scenario and will require the use of standards, as you suggest.</p>
<p>I&#39;m also interested in your thoughts on deprovisioning, metering, and closing the audit and control loop with the enterprise-side Identity GRC system.</p>
<p>Cheers,</p>
<p>Mat Hamlin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fear and loathing in Broomfield: a trip report from Gluecon</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-229</link>
		<dc:creator>Fear and loathing in Broomfield: a trip report from Gluecon</dc:creator>
		<pubDate>Wed, 02 Jun 2010 15:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-229</guid>
		<description>[...] Kaushik (Oracle) offering new approaches to federated provisioning [...]</description>
		<content:encoded><![CDATA[<p>[...] Kaushik (Oracle) offering new approaches to federated provisioning [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Federated Provisioning &#171; Identity Blogger</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-228</link>
		<dc:creator>Federated Provisioning &#171; Identity Blogger</dc:creator>
		<pubDate>Wed, 02 Jun 2010 13:30:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-228</guid>
		<description>[...] 2, 2010 &#183; Leave a Comment  Nishant Kaushik has a great (and funny) slide deck on federated provisioning on his blog. He discusses some distinctions between two flavors of [...]</description>
		<content:encoded><![CDATA[<p>[...] 2, 2010 &middot; Leave a Comment  Nishant Kaushik has a great (and funny) slide deck on federated provisioning on his blog. He discusses some distinctions between two flavors of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention My GlueCon Talk on “Federated Provisioning and the Cloud” – Talking Identity &#124; Nishant Kaushik's Look at the World of Identity Management -- Topsy.com</title>
		<link>http://blog.talkingidentity.com/2010/06/my-gluecon-talk-on-federated-provisioning-and-the-cloud.html/comment-page-1#comment-227</link>
		<dc:creator>Tweets that mention My GlueCon Talk on “Federated Provisioning and the Cloud” – Talking Identity &#124; Nishant Kaushik's Look at the World of Identity Management -- Topsy.com</dc:creator>
		<pubDate>Wed, 02 Jun 2010 01:49:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=879#comment-227</guid>
		<description>[...] This post was mentioned on Twitter by Nishant Kaushik, Naohiro Fujie. Naohiro Fujie said: JIT Prov=クレーム渡し、という所か。 RT @NishantK: Federated Provisioning and the Cloud” http://bit.ly/d5aEZw #IdM #FedProv #GlueCon #Cloud /cc @defrag [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Nishant Kaushik, Naohiro Fujie. Naohiro Fujie said: JIT Prov=クレーム渡し、という所か。 RT @NishantK: Federated Provisioning and the Cloud” <a href="http://bit.ly/d5aEZw" rel="nofollow">http://bit.ly/d5aEZw</a> #IdM #FedProv #GlueCon #Cloud /cc @defrag [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

