<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mike Jones: self-issued &#187; Documentation</title>
	<atom:link href="http://self-issued.info/?feed=rss2&#038;cat=16" rel="self" type="application/rss+xml" />
	<link>http://self-issued.info</link>
	<description>Musings on Digital Identity</description>
	<lastBuildDate>Wed, 01 Sep 2010 00:29:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
	<url>http://self-issued.info/feed_header_image.png</url> 
	<title>Mike Jones: self-issued</title> 
	<link>http://self-issued.info</link> 
	<width>120</width> 
	<height>80</height> 
	</image>		<item>
		<title>AD FS 2.0 Interop Step-By-Step Guide:  Oracle Identity Federation</title>
		<link>http://self-issued.info/?p=333</link>
		<comments>http://self-issued.info/?p=333#comments</comments>
		<pubDate>Mon, 02 Aug 2010 22:44:35 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=333</guid>
		<description><![CDATA[Microsoft has published the second in a series of step-by-step guides on configuring AD FS 2.0 to interoperate with partner products.  This guide describes how to configure AD FS 2.0 and Oracle Identity Federation 11.1.1.2, as delivered in Oracle Identity Management 11.1.1.3, to federate using the SAML 2.0 protocol.  The guide is available [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has published the second in a <a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx">series of step-by-step guides</a> on configuring AD FS 2.0 to interoperate with partner products.  This guide describes how to configure AD FS 2.0 and Oracle Identity Federation 11.1.1.2, as delivered in Oracle Identity Management 11.1.1.3, to federate using the SAML 2.0 protocol.  The guide is available in <a href="http://technet.microsoft.com/en-us/library/ff849212(WS.10).aspx">HTML</a> and <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=46bd1cc0-cbe1-4426-875d-428b25b65f1a">Word</a> formats.  Thanks again to author <a href="http://www.davemartinez.net/">Dave Martinez</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=333</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD FS 2.0 Interop Step-By-Step Guide:  CA Federation Manager</title>
		<link>http://self-issued.info/?p=315</link>
		<comments>http://self-issued.info/?p=315#comments</comments>
		<pubDate>Thu, 08 Jul 2010 06:26:46 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=315</guid>
		<description><![CDATA[Microsoft has published the first of a series of step-by-step guides on configuring AD FS 2.0 to interoperate with partner products.  This guide describes how to configure AD FS 2.0 and CA Federation Manager r12.1 to federate using the SAML 2.0 protocol.  The guide is available in HTML and Word format.  Thanks [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has published the first of a series of step-by-step guides on configuring AD FS 2.0 to interoperate with partner products.  This guide describes how to configure AD FS 2.0 and CA Federation Manager r12.1 to federate using the SAML 2.0 protocol.  The guide is available in <a href="http://technet.microsoft.com/en-us/library/ff754295(WS.10).aspx">HTML</a> and <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=fef76ca4-5677-4356-afb1-196d8f92dc79">Word</a> format.  Thanks go to author Dave Martinez for his expert and detailed treatment of the topic.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=315</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U-Prove Specifications Licensed and Sample Code Released</title>
		<link>http://self-issued.info/?p=272</link>
		<comments>http://self-issued.info/?p=272#comments</comments>
		<pubDate>Tue, 02 Mar 2010 19:17:04 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Claims]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[U-Prove]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=272</guid>
		<description><![CDATA[This morning at the RSA conference, Scott Charney announced that Microsoft has licensed the U-Prove technology under the Open Specification Promise and released sample implementations in C# and Java under the BSD license.  Implementers will be interested in two specifications:  the “U-Prove Cryptographic Specification V1.0”, which documents U-Prove’s cryptographic operations, and “U-Prove Technology [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/U_Prove_RGB.png" alt="U-Prove logo" border="0" hspace="4" /></span>This morning at the RSA conference, Scott Charney announced that Microsoft <a href="https://connect.microsoft.com/content/content.aspx?contentid=12505&#038;siteid=642">has licensed the U-Prove technology</a> under the <a href="http://www.microsoft.com/interop/osp/">Open Specification Promise</a> and released sample implementations in <a href="http://code.msdn.microsoft.com/uprovesdkcsharp">C#</a> and <a href="http://code.msdn.microsoft.com/uprovesdkjava">Java</a> under the BSD license.  Implementers will be interested in <a href="https://connect.microsoft.com/site642/Downloads/DownloadDetails.aspx?DownloadID=26953">two specifications</a>:  the “U-Prove Cryptographic Specification V1.0”, which documents U-Prove’s cryptographic operations, and “U-Prove Technology Integration into the Identity Metasystem V1.0”, which documents how to use U-Prove tokens with WS-Trust.  These specifications are intended to enable interoperable implementations.</p>
<p>The U-Prove technologies enable two key properties:  minimal disclosure and unlinkability.  For more about U-Prove and today’s Community Technology Preview (CTP) release, see the <a href="http://www.microsoft.com/u-prove">Microsoft U-Prove site</a>, the <a href="http://blogs.technet.com/identity/archive/2010/03/02/microsoft-releases-u-prove-technology.aspx">post announcing the release</a>, and <a href="http://blogs.msdn.com/vbertocci/archive/2010/03/02/u-prove-community-technical-preview.aspx">Vittorio’s post</a> (with links to videos).</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=272</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated Federated Identity Product Releases</title>
		<link>http://self-issued.info/?p=263</link>
		<comments>http://self-issued.info/?p=263#comments</comments>
		<pubDate>Fri, 18 Dec 2009 21:14:06 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Claims]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=263</guid>
		<description><![CDATA[Today Microsoft announced the availability of new releases of several identity products:  Active Directory Federation Services (AD FS) 2.0, the Windows Identity Foundation, and CardSpace 2 (which collectively were formerly referred to as “Geneva”), as well as Federation Extensions for SharePoint.  See Announcing the AD FS 2.0 Release Candidate and More and Announcing [...]]]></description>
			<content:encoded><![CDATA[<p>Today Microsoft announced the availability of new releases of several identity products:  Active Directory Federation Services (AD FS) 2.0, the Windows Identity Foundation, and CardSpace 2 (which collectively were formerly referred to as “<a href="http://self-issued.info/?p=151">Geneva</a>”), as well as Federation Extensions for SharePoint.  See <a href="http://blogs.msdn.com/card/archive/2009/12/18/announcing-the-ad-fs-2-0-release-candidate-and-more.aspx">Announcing the AD FS 2.0 Release Candidate and More</a> and <a href="http://blogs.msdn.com/card/archive/2009/12/18/announcing-wif-support-for-windows-server-2003.aspx">Announcing WIF support for Windows Server 2003</a> for the release announcements as well as links to numerous step-by-step guides, samples, docs, and video.  Thanks to all those who did interop work with us (including at <a href="http://self-issued.info/?p=174">Catalyst</a>, <a href="http://self-issued.info/?p=226">Liberty</a>, and <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=9eb1f3c7-84da-40eb-b9aa-44724c98e026">pair-wise</a>) to help ensure that these releases will work well with other’s implementations.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=263</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Card Standard Approved!</title>
		<link>http://self-issued.info/?p=163</link>
		<comments>http://self-issued.info/?p=163#comments</comments>
		<pubDate>Wed, 01 Jul 2009 17:41:39 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=163</guid>
		<description><![CDATA[I’m thrilled to announce that the Identity Metasystem Interoperability Version 1.0 specification has been approved as an OASIS standard, with 56 votes in favor and none against. This standard benefitted substantially from the input received during the process.  Numerous clarifications were incorporated as a result, while still maintaining compatibility with the Identity Selector Interoperability [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" /><img align="right" src="http://self-issued.info/images/oasis.png" hspace="10" alt="OASIS logo" /></span>I’m thrilled to announce that the <a href="http://docs.oasis-open.org/imi/identity/v1.0/identity.html">Identity Metasystem Interoperability Version 1.0</a> specification has been <a href="http://lists.oasis-open.org/archives/imi/200907/msg00000.html">approved as an OASIS standard</a>, with 56 votes in favor and none against. This standard benefitted substantially from the input received during the process.  Numerous clarifications were incorporated as a result, while still maintaining compatibility with the <a href="http://self-issued.info/?p=80">Identity Selector Interoperability Profile V1.5</a> (ISIP 1.5) specification.</p>
<p>While this is often said, this achievement is truly the result of a community effort.  While by no means a comprehensive list, thanks are due to many, including the <a href="http://osis.idcommons.net/">OSIS</a> members whose diligent efforts ensured that Information Cards are interoperable across vendors and platforms, the <a href="http://informationcard.net/">Information Card Foundation</a> members for their adoption and thought leadership work, and the <a href="http://www.oasis-open.org/committees/membership.php?wg_abbrev=imi">IMI TC members</a>, including co-chairs Marc Goodner and Tony Nadalin, and Mike McIntosh, who was my co-editor.  <a href="http://www.incontextblog.com/">Paul Trevithick</a> and Mary Ruddy get enormous credit for starting and leading the <a href="http://www.eclipse.org/higgins/">Higgins Project</a>, as does <a href="http://virtualsoul.org/">Dale Olds</a> for the <a href="http://www.bandit-project.org/">Bandit Project</a>.   <a href="http://www.identitywoman.net/">Kaliya Hamlin</a> and <a href="http://www.windley.com/">Phil Windley</a> were instrumental behind the scenes by running the <a href="http://iiw.idcommons.net/">IIW</a>s.  <a href="http://ignisvulpis.blogspot.com/">Axel Nennker</a> has been a tireless force, producing both ideas and software, as has <a href="http://eternallyoptimistic.com/">Pamela Dingle</a>.  <a href="http://www.burtongroupblogs.com/jamielewis/">Jamie Lewis</a>, <a href="http://notabob.blogspot.com/">Bob Blakley</a>, and <a href="http://www.craigburton.com/">Craig Burton</a> all provided insightful guidance on the practical aspects of birthing a new technology.  Arun Nanda deserves enormous thanks for doing the heavy lifting to produce the ISIP 1.0 spec.  And of course, none of this would have occurred without the leadership and vision of <a href="http://www.identityblog.com/">Kim Cameron</a>.  Thanks one and all!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=163</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PPID, ClientPseudonym, and Signing Key Computation Examples</title>
		<link>http://self-issued.info/?p=128</link>
		<comments>http://self-issued.info/?p=128#comments</comments>
		<pubDate>Thu, 02 Apr 2009 06:14:08 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=128</guid>
		<description><![CDATA[Microsoft published a knowledge base article today giving examples of intermediate data values produced when generating actual PPID, ClientPseudonym, and Signing Key values.  These examples use the algorithms specified in ISIP 1.5 to go behind the scenes of specific OSIS interop computations.
In particular, the article shows how to correctly generate the PPID and Signing [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" />Microsoft published a <a href="http://support.microsoft.com/kb/969419">knowledge base article</a> today giving examples of intermediate data values produced when generating actual PPID, ClientPseudonym, and Signing Key values.  These examples use the algorithms specified in <a href="http://self-issued.info/?p=80">ISIP 1.5</a> to go behind the scenes of specific <a href="http://osis.idcommons.net/">OSIS</a> interop computations.</p>
<p>In particular, the article shows how to correctly generate the PPID and Signing Key values for the test <a href="http://osis.idcommons.net/wiki/I5:FeatureTest-Selector_Constructs_Site-Specific_Identifiers_for_Self-Issued_Cards">Selector_Constructs_Site-Specific_Identifiers_for_Self-Issued_Cards</a> and how to generate the ClientPseudonym value for the test <a href="http://osis.idcommons.net/wiki/I5:FeatureTest-Selector_Support_for_Non-Auditing_Cards">Selector_Support_for_Non-Auditing_Cards</a>.  These examples are also highly relevant to the tests <a href="http://osis.idcommons.net/wiki/I5:FeatureTest-Selector_PPID_Construction_for_RP_using_EV_SSL">Selector_PPID_Construction_for_RP_using_EV_SSL</a>, <a href="http://osis.idcommons.net/wiki/I5:FeatureTest-Selector_Support_for_Auditing-Optional_Cards">Selector_Support_for_Auditing-Optional_Cards</a>, and <a href="http://osis.idcommons.net/wiki/I5:FeatureTest-Selector_Support_for_Auditing_Cards">Selector_Support_for_Auditing_Cards</a>.</p>
<p>Thanks to Toland Hon of the “Geneva” test team for writing this useful article.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=128</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PPID Compatibility Note for Sites Accepting Self-Issued Information Cards</title>
		<link>http://self-issued.info/?p=83</link>
		<comments>http://self-issued.info/?p=83#comments</comments>
		<pubDate>Wed, 27 Aug 2008 21:54:04 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=83</guid>
		<description><![CDATA[Relying Parties often identify subjects using the Private Personal Identifier (PPID) claim and Signing Key values sent by an Information Card.  Thus, it is important that the PPID and Signing Key values produced by a card be stable and long-lived.
Unfortunately, the PPIDs and Signing Keys generated by self-issued (a.k.a. personal) Information Cards using the [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" />Relying Parties often identify subjects using the Private Personal Identifier (PPID) claim and Signing Key values sent by an Information Card.  Thus, it is important that the PPID and Signing Key values produced by a card be stable and long-lived.</span></p>
<p>Unfortunately, the PPIDs and Signing Keys generated by self-issued (a.k.a. personal) Information Cards using the algorithm originally shipped with Windows CardSpace (and documented in <a href="http://self-issued.info/?p=8">ISIP V1.0</a>) for sites using regular certificates were not stable under several important conditions.  Therefore, after considering industry feedback on the long-term problems that this continued instability would cause, and in consultation with other Identity Selector authors, a decision was made to change these algorithms in a way that will provide much better long-term stability of these important Subject identifiers for Relying Parties.  The new algorithm is documented in the <a href="http://self-issued.info/?p=80">Identity Selector Interoperability Profile (ISIP) V1.5</a>.</p>
<p>This change shipped with the version of Windows CardSpace in the <a href="http://blogs.msdn.com/somasegar/archive/2008/08/11/service-pack-1-for-vs-2008-and-net-fx-3-5-released.aspx">.NET Framework 3.5 Service Pack 1</a>.  This service pack will be installed by Windows Update on systems with the .NET Framework 2.0, 3.0, and 3.5 in the coming months.  I know that the <a href="http://www.bandit-project.org/">Bandit</a> and <a href="http://www.eclipse.org/higgins/">Higgins</a> projects have implemented the new algorithm as well.</p>
<p>Unfortunately, this change means that the PPIDs and Signing Keys for self-issued cards used at existing Relying Parties that employ standard SSL certificates will change after this installation.</p>
<p><strong>What Sites Need to Do</strong></p>
<p>Sites need to ensure that they have tested mechanisms in place to enable their users to re-associate their Information Card with their account when the card’s PPID and Signing Key change.  The good news is that these mechanisms are likely already in place in the form of “lost card” handling procedures.</p>
<p>When the card is used after the update, it will appear to be an unrecognized card.  Just as sites’ lost card procedures can be used today to associate a new Information Card with their account, these same procedures can be used to re-associate the existing card with the account after these changes.</p>
<p>These lost card procedures will typically involve sending the user a message at the e-mail address of record for the account.  This message contains a link that enables them to associate an Information Card with their account.  This flow is nearly identical to the “lost password” flows often found on sites.  Best practices for lost card handling are documented in the “Enabling Information Card Recovery” section of <a href="http://go.microsoft.com/fwlink/?LinkId=98051">Patterns for Supporting Information Cards at Web Sites: Personal Cards for Sign up and Signing In</a>.</p>
<p><strong>Additional Steps Sites Could Take</strong></p>
<p>In the short term, sites could also choose to add text to their Information Card login pages warning users that their existing cards will not be recognized as being associated with their accounts after the .NET update, and directing them to use the “lost card” feature of the site to remedy this situation.</p>
<p><strong>EV and no-SSL Sites Not Affected</strong></p>
<p>None of this affects sites using Extended Validation (EV) certificates or sites not using SSL certificates.  These algorithms were already stable and have not changed.  No action is required in these cases.</p>
<p><strong>Background on the Problem</strong></p>
<p>Because the original PPID and Signing Key algorithms used the entire certificate chain, these values could change under several circumstances:</p>
<ul>
<li>First, as sites renew their certificates, it is common for the certificate chain for the new cert to differ from the old one.  This would change the PPID, breaking the user’s self-issued cards at those sites.  And of course, the chain always changes if the site changes its certificate provider.</li>
<li>Second, because the algorithm for converting the bytes of the chain certificates into characters was not fully specified by ISIP V1.0 for some OIDs, for some kinds of certificates, different Identity Selectors produced different results for the PPID claim, Signing Key, Client Pseudonym PPID, and IP Identifier values.</li>
<li>Finally, in ISIP V1.0, the PPID for a site using a non-EV certificate is different than the PPID for a site that uses an EV certificate, even in the case where the non-EV leaf cert content meets the EV issuance criteria.  This means that when a site upgraded to using an EV certificate, user’s cards would stop working at that site.</li>
</ul>
<p><strong>Overview of the Solution</strong></p>
<p>To address these issues, the computation of the PPID and Signing Key for sites using regular certificates has been changed to no longer include information from the certificate chain, but only information from the leaf certificate.  This will provide stability both when certificates are renewed and when a certificate is obtained from a new issuer.</p>
<p>Furthermore, the new algorithm generates the same PPID values for sites using EV and non-EV certificates with the same leaf certificate information, while generating different Signing Keys.  This will help enable a smooth migration path for sites upgrading from non-EV to EV certificates because the PPID remaining the same can be used as evidence that the same card is being used before and after the certificate upgrade.</p>
<p>More about the specifics of the algorithm change can be found in Section 8.6.1 of <a href="http://self-issued.info/?p=80">ISIP V1.5</a> and additional guidance and commentary can be found in the corresponding section of the ISIP V1.5 Guide.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=83</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WS-Addressing Identity Extension Published</title>
		<link>http://self-issued.info/?p=82</link>
		<comments>http://self-issued.info/?p=82#comments</comments>
		<pubDate>Wed, 27 Aug 2008 17:53:58 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=82</guid>
		<description><![CDATA[IBM and Microsoft just published the specification “Application Note: Web Services Addressing Endpoint References and Identity” at http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/.  This specification is referenced by the Identity Selector Interoperability Profile (ISIP) and is covered by Microsoft’s Open Specification Promise (OSP).  This completes the publication and licensing under the OSP of all specifications that Information Cards [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" />IBM and Microsoft just published the specification “<a href="http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/WS-AddressingAndIdentity.pdf">Application Note: Web Services Addressing Endpoint References and Identity</a>” at <a href="http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/">http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/</a>.  This specification is referenced by the Identity <a href="http://self-issued.info/?p=80">Selector Interoperability Profile (ISIP)</a> and is covered by Microsoft’s <a href="http://www.microsoft.com/interop/osp/">Open Specification Promise (OSP)</a>.  This completes the publication and licensing under the OSP of all specifications that Information Cards based upon the ISIP depend upon.</span></p>
<p class="body" style="margin-left:.5in"><font size="-2">Note:  While ISIP 1.5 references the addressing identity extension using a date of July 2008, it was actually published in August.  This is an erratum in the ISIP that resulted from the publication of the extension taking longer than anticipated – not a reference to a different document.  Both consistently use the URL <a href="http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/">http://schemas.xmlsoap.org/ws/2006/02/addressingidentity/</a>.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=82</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity Selector Interoperability Profile V1.5</title>
		<link>http://self-issued.info/?p=80</link>
		<comments>http://self-issued.info/?p=80#comments</comments>
		<pubDate>Mon, 11 Aug 2008 21:21:59 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=80</guid>
		<description><![CDATA[I am pleased to announce the publication of the Identity Selector Interoperability Profile V1.5 and companion guides.  The ISIP (as it’s come to be called) documents the protocols and data formats used by Windows CardSpace so as to enable others to build compatible Information Card software.
Version 1.0 of these documents corresponded to the.NET Framework [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" />I am pleased to announce the publication of the <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b94817fc-3991-4dd0-8e85-b73e626f6764&#038;DisplayLang=en">Identity Selector Interoperability Profile V1.5 and companion guides</a>.  The ISIP (as it’s come to be called) documents the protocols and data formats used by Windows CardSpace so as to enable others to build compatible Information Card software.</span></p>
<p>Version 1.0 of these documents corresponded to the.NET Framework 3.0 version of CardSpace.  Version 1.5 corresponds to CardSpace as of .NET Framework 3.5 Service Pack 1.  Like <a href="http://self-issued.info/?p=8">the previous version</a>, ISIP 1.5 is licensed under Microsoft’s <a href="http://www.microsoft.com/interop/osp/">Open Specification Promise</a>.</p>
<p>Significant new content covers:</p>
<ul>
<li>Relying Parties without SSL certificates</li>
<li>Use of WS-Trust 1.3 and WS-SecurityPolicy 1.2</li>
<li>Relying Party STSs</li>
<li>More stable PPID algorithm</li>
<li>Specifications for computing ic:IssuerId and ic:IssuerName</li>
<li>Token references by Identity Providers via wst:RequestedAttachedReference and wst:RequestedUnattachedReference elements</li>
<li>Custom issuer information in cards</li>
<li>Custom error messages</li>
<li>Clarification that an ic:MasterKey is required for managed cards</li>
<li>Plus numerous of clarifications that were found by others building Information Card software – especially during the <a href="http://osis.idcommons.net/">OSIS interops</a></li>
</ul>
<p>The three new document versions are:</p>
<ul>
<li><a href="http://download.microsoft.com/download/1/1/a/11ac6505-e4c0-4e05-987c-6f1d31855cd2/Identity_Selector_Interoperability_Profile_V1.5.pdf">Identity Selector Interoperability Profile V1.5</a> by Arun Nanda and yours truly, which provides normative specifications of the protocol elements and data interchange formats employed by CardSpace-compatible Identity Selectors and other interoperable Information Card components,</li>
<li><a href="http://download.microsoft.com/download/1/1/a/11ac6505-e4c0-4e05-987c-6f1d31855cd2/Identity_Selector_Interoperability_Profile_V1.5_Guide.pdf">An Implementer’s Guide to the Identity Selector Interoperability Profile V1.5</a>, co-authored by Microsoft and Ping Identity, which provides informative advice and commentary on how to use the ISIP specifications when building interoperable Information Card software, and</li>
<li><a href="http://download.microsoft.com/download/1/1/a/11ac6505-e4c0-4e05-987c-6f1d31855cd2/Identity_Selector_Interoperability_Profile_V1.5_Web_Guide.pdf">A Guide to Using the Identity Selector Interoperability Profile V1.5 within Web Applications and Browsers</a>, also by yours truly, which provides informative advice and commentary on how these specifications are used by Web sites that accept Information Cards and by Web browsers when communicating with these sites.</li>
</ul>
<p>Thanks to the literally dozens of you who provided comments on ways to improve the ISIP and companion docs and who reviewed drafts of this material.  This version of the docs benefited substantially from your detailed knowledge of and experience with the previous spec gained through implementing interoperable Information Card software.</p>
<p>Finally, I’d like to thank the members of the CardSpace team who diligently documented many of these features on the <a href="http://blogs.msdn.com/card/">CardSpace Team Blog</a> in advance of their publication under the ISIP.  Your work let the industry gain early experience with implementing these features and was a tremendous resource to me as I was producing these versions of the documents.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=80</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>CardSpace Consumer Website</title>
		<link>http://self-issued.info/?p=78</link>
		<comments>http://self-issued.info/?p=78#comments</comments>
		<pubDate>Fri, 04 Jul 2008 05:56:31 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=78</guid>
		<description><![CDATA[Microsoft recently created a Consumer Website for CardSpace to educate end-users about Windows CardSpace and Information Cards.  This complements the developer-focused information at the MSDN CardSpace site and the CardSpace Community Site.
No, it’s not the kind of content targeted at regular readers of this blog – especially the short video – but then, that’s [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/vista_logo_75x75.jpg" alt="Windows logo" />Microsoft recently created a <a href="http://www.microsoft.com/windows/products/winfamily/cardspace/">Consumer Website for CardSpace</a> to educate end-users about Windows CardSpace and Information Cards.  This complements the developer-focused information at the <a href="http://msdn.microsoft.com/CardSpace">MSDN CardSpace site</a> and the <a href="http://netfx3.com/content/WindowsCardspaceHome.aspx">CardSpace Community Site</a>.</p>
<p>No, it’s not the kind of content targeted at regular readers of this blog – especially the <a href="http://download.microsoft.com/download/8/E/7/8E7032E0-D1D0-4AA3-BB5E-012936B76805/Film2_Home_V9.wmv">short video</a> – but then, that’s kind of the point. :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=78</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://download.microsoft.com/download/8/E/7/8E7032E0-D1D0-4AA3-BB5E-012936B76805/Film2_Home_V9.wmv" length="14685925" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>ANSI-BBB Identity Theft Prevention and Identity Management Standards Panel Final Report</title>
		<link>http://self-issued.info/?p=55</link>
		<comments>http://self-issued.info/?p=55#comments</comments>
		<pubDate>Thu, 07 Feb 2008 07:58:21 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=55</guid>
		<description><![CDATA[The ANSI-BBB Identity Theft Prevention and Identity Management Standards Panel recently issued its final report.  Quoting from the report announcement:

Launched in September 2006, the IDSP was established by the American National Standards Institute (ANSI) and Better Business Bureau (BBB) to identify and catalog existing standards, guidelines, and best practices related to identity theft prevention.
Panel [...]]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/images/idsp_07.jpg" alt="ANSI-BBB Identity Theft Prevention and Identity Management Standards Panel" /></span>The ANSI-BBB Identity Theft Prevention and Identity Management Standards Panel recently issued its <a href="http://www.ansi.org/standards_activities/standards_boards_panels/idsp/report_webinar08.aspx">final report</a>.  Quoting from the report announcement:</p>
<blockquote><p>
Launched in September 2006, the <a href="http://www.ansi.org/idsp/">IDSP</a> was established by the <a href="http://www.ansi.org/">American National Standards Institute</a> (ANSI) and <a href="http://www.bbb.org/">Better Business Bureau</a> (BBB) to identify and catalog existing standards, guidelines, and best practices related to identity theft prevention.<br />
Panel members considered the entire life cycle of identity management: from the issuance of identity documents by government and commercial entities, to the acceptance and exchange of identity data, and to the ongoing maintenance and management of identity information. Hundreds of documents – including the applicable laws, regulations, proposed legislation, white papers, and research studies and reports – are identified in the catalog.<br />
The report also includes recommendations for business and government agencies to:</p>
<ul>
<li>enhance the security of identity issuance processes to facilitate greater interoperability between the government and commercial sectors; </li>
<li>improve the integrity of identity credentials; </li>
<li>strengthen best practices for authentication; </li>
<li>augment data security management best practices such as the use and storage of Social Security numbers; </li>
<li>create uniform guidance for organizations on data breach notification and remediation; </li>
<li>increase consumer understanding of ID theft preventative strategies, including the benefits and limitations of security freezes.</li>
</ul>
</blockquote>
<p>This report provides one of the most comprehensive looks to date at the problem of identity theft and the fraud that accompanies it.  It both surveys the current identity landscape and makes recommendations for business, government, and consumers to mitigate these threats both in the offline and online environments.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=55</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Come ’n get it!</title>
		<link>http://self-issued.info/?p=54</link>
		<comments>http://self-issued.info/?p=54#comments</comments>
		<pubDate>Thu, 10 Jan 2008 19:03:01 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=54</guid>
		<description><![CDATA[Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities by Vittorio Bertocci, Garrett Serack, and Caleb Baker, is now in print!.  As I wrote for the “praise page” of the book:
Chock full of useful, actionable information covering the “whys”, “whats”, and “hows” of employing safer, easier-to-use, privacy-preserving digital identities.  [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/Understanding_Windows_CardSpace_cover.jpg" align="right" alt="Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities" /><a href="http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Independent/dp/0321496841/">Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities</a> by <a href="http://blogs.msdn.com/vbertocci/archive/2008/01/08/and-the-physical-copies-are-here.aspx">Vittorio Bertocci</a>, <a href="http://www.fearthecowboy.com/">Garrett Serack</a>, and <a href="http://www.informit.com/authors/bio.aspx?a=4dd19005-732f-435a-ba69-fbc59f569abb&#038;rl=1">Caleb Baker</a>, is now in print!.  As I wrote for the “praise page” of the book:</p>
<blockquote><p>Chock full of useful, actionable information covering the “whys”, “whats”, and “hows” of employing safer, easier-to-use, privacy-preserving digital identities.  Insightful perspectives, on topics from cryptography and protocols to user interfaces and online threats to businesses drivers, make this an essential resource!</p></blockquote>
<p>Come ’n get it!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=54</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>OpenID 2.0 Specifications Complete</title>
		<link>http://self-issued.info/?p=48</link>
		<comments>http://self-issued.info/?p=48#comments</comments>
		<pubDate>Wed, 05 Dec 2007 20:52:32 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=48</guid>
		<description><![CDATA[This morning at the Internet Identity Workshop, the OpenID Foundation announced that the OpenID 2.0 Specification and a set of related specifications are now complete.  Furthermore, Intellectual Property Contribution Agreements have been executed by all the contributors to these specifications.
Here’s a camera-phone photo of Dick Hardt of Sxip Identity, Josh Hoyt of JanRain, and [...]]]></description>
			<content:encoded><![CDATA[<p>This morning at the <a href="http://www.windley.com/events/iiw2007b/">Internet Identity Workshop</a>, the <a href="http://openid.net/foundation/">OpenID Foundation</a> announced that the <a href="http://openid.net/developers/specs/">OpenID 2.0 Specification and a set of related specifications</a> are now complete.  Furthermore, <a href="http://openid.net/ipr/Non-Assertion-Agreement/executed/">Intellectual Property Contribution Agreements have been executed</a> by all the contributors to these specifications.</p>
<p>Here’s a camera-phone photo of <a href="http://identity20.com/">Dick Hardt</a> of <a href="http://www.sxip.com/">Sxip Identity</a>, <a href="http://claimid.com/j3h/">Josh Hoyt</a> of <a href="http://janrain.com/">JanRain</a>, and <a href="http://daveman692.livejournal.com/">David Recordon</a> of <a href="http://www.sixapart.com/">Six Apart</a> making the announcement.  Congratulations to the OpenID community on this significant accomplishment!</p>
<p><span class="plain"><a href="http://self-issued.info/images/OpenID_Announcement.jpg"><img src="http://self-issued.info/images/OpenID_Announcement_small.jpg" alt="Dick Hardt, Josh Hoyt, and David Recordon announcing that the OpenID 2.0 specifications are complete" /></a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=48</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding Windows CardSpace Book</title>
		<link>http://self-issued.info/?p=41</link>
		<comments>http://self-issued.info/?p=41#comments</comments>
		<pubDate>Thu, 01 Nov 2007 04:08:36 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=41</guid>
		<description><![CDATA[I highly recommend the new book Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities by Vittorio Bertocci, Garrett Serack, and Caleb Baker.  As I wrote for the “praise page” on the back of the book after reading the current draft:

<blockquote>Chock full of useful, actionable information covering the “whys”, “whats”, and “hows” of employing safer, easier-to-use, privacy-preserving digital identities.  Insightful perspectives, on topics from cryptography and protocols to user interfaces and online threats to businesses drivers, make this an essential resource!</blockquote>
]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/Understanding_Windows_CardSpace_cover.jpg" align="right" alt="Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities" />I highly recommend the new book <a href="http://www.amazon.com/Understanding-Windows-CardSpace-Introduction-Independent/dp/0321496841/">Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities</a> by <a href="http://blogs.msdn.com/vbertocci/archive/2007/10/17/first-draft-of-the-book-understanding-windows-cardspace-available-on-rough-cuts.aspx">Vittorio Bertocci</a>, <a href="http://www.fearthecowboy.com/">Garrett Serack</a>, and Caleb Baker.  As I wrote for the “praise page” of the book after reading the current draft:</p>
<blockquote><p>Chock full of useful, actionable information covering the “whys”, “whats”, and “hows” of employing safer, easier-to-use, privacy-preserving digital identities.  Insightful perspectives, on topics from cryptography and protocols to user interfaces and online threats to businesses drivers, make this an essential resource!</p></blockquote>
<p>A must-have for anyone deploying or considering deploying Information Cards.  And if you can’t wait for the book to be published, you can also <a href="http://safari.oreilly.com/9780321496843">purchase a first draft</a> of the book from Rough Cuts.  Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=41</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>User-Centric Identity Interop at Catalyst in Barcelona</title>
		<link>http://self-issued.info/?p=39</link>
		<comments>http://self-issued.info/?p=39#comments</comments>
		<pubDate>Wed, 24 Oct 2007 20:10:25 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Bandit Project]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Higgins Project]]></category>
		<category><![CDATA[I-names]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Interoperability]]></category>
		<category><![CDATA[JanRain]]></category>
		<category><![CDATA[LiveID]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Pamela Project]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Shibboleth]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=39</guid>
		<description><![CDATA[Last night <a href="http://osis.netmesh.org/wiki/Main_Page">OSIS</a> and the <a href="http://www.burtongroup.com/">Burton Group</a> held the third in a series of user-centric identity Interop events where companies and projects building user-centric identity software components came together and tested the interoperation of their software together.  Following on the Interops at <a href="http://self-issued.info/?p=12">IIW in May</a> and <a href="http://self-issued.info/?p=25">Catalyst in June</a>, the participants continued their joint work of ensuring that the identity software we’re all building works great together.
]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/Barcelona_Interop_2007_Participants.jpg" alt="Logos of Barcelona Interop Participants 2007" /></p>
<p>Last night <a href="http://osis.netmesh.org/wiki/Main_Page">OSIS</a> and the <a href="http://www.burtongroup.com/">Burton Group</a> held the third in a series of user-centric identity Interop events where companies and projects building user-centric identity software components came together and tested the interoperation of their software together.  Following on the Interops at <a href="http://self-issued.info/?p=12">IIW in May</a> and <a href="http://self-issued.info/?p=25">Catalyst in June</a>, the participants continued their joint work of ensuring that the identity software we’re all building works great together.</p>
<p>This Interop had a broader scope along several dimensions than the previous ones:</p>
<ul>
<li>We welcomed <strong>new participants</strong> <a href="http://www.ate-software.net/ATEHome/ATE/ate.aspx">a.t.e Software</a>, <a href="http://www.fokus.fraunhofer.de/home/index.php?lang=en">Fraunhofer</a>, <a href="http://janrain.com/">JanRain</a>, <a href="http://linksafe.name/">LinkSafe</a>, <a href="http://ootao.com/">ooTao</a>, <a href="http://www.sun.com/">Sun Microsystems</a>, <a href="http://w1.siemens.com/en/entry.html">Siemens</a>, and <a href="http://www.thoughtworks.com/">ThoughtWorks</a>.</li>
<li>We tested interoperation of <strong>OpenID</strong> software (including <strong>i-name</strong> software) in addition to Information Card software.</li>
<li>Several kinds of <strong>interop between Information Card and OpenID software</strong> were demonstrated, including:
<ol>
<li>OpenID providers implementing the <a href="http://self-issued.info/?p=15">OpenID phishing-resistant authentication specification</a> using Information Cards to enable phishing-resistant sign-in to OpenIDs, and</li>
<li>using <a href="http://self-issued.info/?p=27">OpenID Information Cards</a> to supply OpenIDs to OpenID relying parties.</li>
</ol>
</li>
<li>Unlike previous Interops, the endpoints and testing results are all <a href="http://osis.netmesh.org/wiki/I2-Barcelona">publicly available</a> so that others can benefit from them.</li>
<li>Many of the participants have committed to keeping their sites up beyond Catalyst to allow for continued public interop testing.  For instance, Microsoft’s sites will remain up at <a href="http://www.federatedidentity.net/">http://www.federatedidentity.net/</a>.</li>
</ul>
<p>An excerpt from <a href="http://identityblog.burtongroup.com/bgidps/2007/10/osis-user-centr.html">Bob Blakley’s insightful-as-always commentary</a> on the Interop is:</p>
<blockquote><p>
The participants have <a href="http://osis.netmesh.org/wiki/I2_Results">posted their results on the wiki</a>, and a few words are in order about these results.  The first thing you’ll notice is that there are a significant number of “failure” and “issue” results.  This is very good news for two reasons.</p>
<p>The first reason it’s good news is that it means enough new test cases were designed for this interop to uncover new problems.  What you don’t see in the matrix is that when testing began, there were even more failures – which means that a lot of the new issues identified during the exercise have already been fixed.</p>
<p>The second reason the “failure” and “issue” results are good news is that they’re outnumbered by the successes.  When you consider that the things tested in Barcelona were all identified as problems at the previous interop, you’ll get an idea of how much work has been done by the OSIS community in only 4 months to improve interoperability and agree on standards of component behavior.
</p></blockquote>
<p>Be sure to read his full post for more details on what the participants accomplished together.  And of course, this isn’t the end of the story.   An even wider and deeper Interop event is planned for the <a href="http://www.rsaconference.com/2008/US/">RSA Conference in April 2008</a>.  Great progress on building the Internet identity layer together!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=39</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Information Card Icon Usage Guidelines Updated</title>
		<link>http://self-issued.info/?p=38</link>
		<comments>http://self-issued.info/?p=38#comments</comments>
		<pubDate>Tue, 23 Oct 2007 13:26:17 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=38</guid>
		<description><![CDATA[During <a href="http://catalyst.burtongroup.com/NA07/">Catalyst in San Francisco</a> we announced the now-familiar Information Card icon and its accompanying usage guidelines.  Since then we've received community feedback on clarifications we could make to the guidelines.  In response, we’ve publish an <a href="http://self-issued.info/infocard_icon/Information%20Card%20Icon%20Guidelines.pdf">updated version of the guidelines</a> addressing that feedback and an accompanying <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ce99e033-39a8-4bc5-9014-60ed0b560d0e&#038;displaylang=en">updated complete icon zip file</a> during <a href="http://catalyst.burtongroup.com/EU07/">Catalyst in Barcelona</a>.]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img align="right" src="http://self-issued.info/infocard_icon/images/infocard_114x80.png" hspace="2" alt="Information Card Icon" />During <a href="http://catalyst.burtongroup.com/NA07/">Catalyst in San Francisco</a> we announced the now-familiar Information Card icon and its accompanying usage guidelines.  Since then we&#8217;ve received community feedback on clarifications we could make to the guidelines.  In response, we’ve publish an <a href="http://self-issued.info/infocard_icon/Information%20Card%20Icon%20Guidelines.pdf">updated version of the guidelines</a> addressing that feedback and an accompanying <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ce99e033-39a8-4bc5-9014-60ed0b560d0e&#038;displaylang=en">updated complete icon zip file</a> during <a href="http://catalyst.burtongroup.com/EU07/">Catalyst in Barcelona</a>.</span></p>
<p>Specifically, we were asked if we could be clearer that the icon can be used in contexts discussing and promoting Information Cards, not just in software, and some felt that the spacing guidelines were overly restrictive.  My favorite feedback along these lines came from <a href="http://virtualsoul.org/">Dale Olds</a>, in his wonderful <a href="http://virtualsoul.org/blog/2007/08/28/fashions-in-information-card-beachware/">Fashions in information card beachware</a> post, where he wrote:</p>
<blockquote><p>Thanks to <a href="http://self-issued.info/">Mike</a> for the information card shirt. I try to wear it in compliance with the logo <a href="http://self-issued.info/?p=17">usage guidelines</a>, but I think I probably sometimes stand too close to other images and I spilled some salsa on it. I’ll keep working on it.</p></blockquote>
<p>So don’t worry Dale…  I’m glad you’re enjoying your shirt and displaying the icon to the world.  Heck, you can even print some cool new ones of your own using it if you want.  (And if you do, it’d love it if you saved one for me!)</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=38</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New CardSpace Team Blog, New CardSpace Features</title>
		<link>http://self-issued.info/?p=31</link>
		<comments>http://self-issued.info/?p=31#comments</comments>
		<pubDate>Tue, 25 Sep 2007 16:37:33 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=31</guid>
		<description><![CDATA[I’m pleased to announce two great developments.  First, the CardSpace team just established a team blog.  The blog will provide a direct voice for the team members to communicate about their work.
Second, on the blog they’ve started a series of posts about new features to come in the .Net Framework 3.5, which will [...]]]></description>
			<content:encoded><![CDATA[<p>I’m pleased to announce two great developments.  First, the CardSpace team <a href="http://blogs.msdn.com/card/archive/2007/09/25/first-post-for-the-cardspace-team-blog.aspx">just established</a> a <a href="http://blogs.msdn.com/card/">team blog</a>.  The blog will provide a direct voice for the team members to communicate about their work.</p>
<p>Second, on the blog they’ve started a series of posts about new features to come in the .Net Framework 3.5, which will ship with Windows Vista Service Pack 1 and be available as a free download for Windows XP and Windows Server 2003.  <a href="http://blogs.msdn.com/card/archive/2007/09/25/deploy-cardspace-on-your-site-without-a-ssl-certificate.aspx">The first post</a> in the series describes the ability to use Information Cards at relying parties over http connections, without requiring a SSL certificate.  This was a feature a number of you had asked for and the team responded.</p>
<p><a href="http://blogs.msdn.com/card/">Subscribe to the blog</a> and read the series!  Also, check out <a href="http://blogs.msdn.com/vbertocci/archive/2007/09/25/windows-cardspace-will-work-without-https-too.aspx">Vittorio Bertocci’s useful commentary</a> on the no-SSL feature.</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=31</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Information Cards for OpenIDs</title>
		<link>http://self-issued.info/?p=27</link>
		<comments>http://self-issued.info/?p=27#comments</comments>
		<pubDate>Sun, 26 Aug 2007 22:45:27 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Phishing Resistance]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=27</guid>
		<description><![CDATA[Sxip Identity just finished a <a href="https://openidcards.sxip.com/spec/openid-infocards.html">draft specification</a> that enables a really useful form of convergence between OpenIDs and Information Cards:  presenting your OpenID as an Information Card you select rather than as a string you type.  Johnny Bufu’s <a href="http://openid.net/pipermail/general/2007-August/003160.html">OpenID general mailing list note</a> introduces this specification for community review.

This combination has several advantages over standard OpenID usage.  First, there’s no OpenID string to type when you use your OpenID, which should make OpenIDs easier for more people to use.  Second, this is a phishing-resistant authentication method.  Finally, it lets you recognize and choose your OpenID visually, based on the card graphics supplied by the OpenID provider.

Sxip also backed this specification by a sample implementation, which you can check out at <a href="https://openidcards.sxip.com/">https://openidcards.sxip.com/</a>.]]></description>
			<content:encoded><![CDATA[<p>Sxip Identity just finished a <a href="https://openidcards.sxip.com/spec/openid-infocards.html">draft specification</a> that enables a really useful form of convergence between OpenIDs and Information Cards:  presenting your OpenID as an Information Card you select rather than as a string you type.  Johnny Bufu’s <a href="http://openid.net/pipermail/general/2007-August/003160.html">OpenID general mailing list note</a> introduces this specification for community review.</p>
<p>This combination has several advantages over standard OpenID usage.  First, there’s no OpenID string to type when you use your OpenID, which should make OpenIDs easier for more people to use.  Second, this is a phishing-resistant authentication method.  Finally, it lets you recognize and choose your OpenID visually, based on the card graphics supplied by the OpenID provider.</p>
<p>Sxip also backed this specification by a sample implementation, which you can check out at <a href="https://openidcards.sxip.com/">https://openidcards.sxip.com/</a>.  Now for some more details….</p>
<p>Here’s how it works:  In this model, the OpenID relying party asks for an OpenID Information Card using an object tag on the page rather than having the user type the OpenID as a string (while probably also giving the user the option to instead type in the string for backwards compatibility).  The user’s Identity Selector then lets the user choose which OpenID card to send to the site.  The card transmits the actual OpenID string to the site as a claim.  From that point on, standard OpenID protocol interactions ensue.</p>
<p>For instance, the <a href="https://openidcards.sxip.com/demorp/">sample relying party</a> page asks you to “<strong>Login with an OpenID InfoCard</strong>” and requests the card using this evocative graphic:</p>
<div align="center"><img src="http://self-issued.info/images/openid_infocard.png" alt="OpenID InfoCard" /></div>
<p>Upon clicking the graphic, my identity selector is invoked, which shows me that I can use this OpenID Information Card at the site (which I’d previously obtained <a href="https://openidcards.sxip.com/TokenService/">here</a>):</p>
<div align="center"><img src="http://self-issued.info/images/Sxip_OpenID_InfoCard.bmp" alt="Sxip OpenID InfoCard" /></div>
<p>After that, the sample performed a standard OpenID attribute exchange and the relying party greeted me with:</p>
<p style="margin-left:.25in">Welcome! You have logged in using your <strong>https://openidcards.sxip.com/i/mbj</strong> OpenID identifier.<br />
<br />
Phone: (omitted)<br />
Country: USA<br />
Email: mbj@microsoft.com<br />
City: Redmond<br />
Address: One Microsoft Way, Building 40/5138<br />
LastName: Jones<br />
FirstName: Mike</p>
<p>Behind the scenes, the relying party had received this OpenID assertion:</p>
<pre style="margin-left:.25in"><code>&lt;openid:OpenIDToken xmlns:openid="http://specs.openid.net/auth/2.0"&gt;openid.ns:http://specs.openid.net/auth/2.0
openid.op_endpoint:https://openidcards.sxip.com/op/
openid.claimed_id:https://openidcards.sxip.com/i/mbj
openid.response_nonce:2007-08-26T20:55:34Z0
openid.mode:id_res
openid.identity:https://openidcards.sxip.com/i/mbj
openid.return_to:https://openidcards.sxip.com/demorp/
openid.assoc_handle:f27d249fc4108198
openid.signed:op_endpoint,claimed_id,identity,return_to,response_nonce,assoc_handle
openid.sig:gKKpDjEbgByJo48Q800Jq4gCJng=
openid.ns.ext1:http://openid.net/srv/ax/1.0-draft4
openid.ext1.mode:fetch_response
openid.ext1.type.attr1:http://axschema.org/contact/phone/default
openid.ext1.value.attr1:(omitted)
openid.ext1.type.attr2:http://axschema.org/contact/country/home
openid.ext1.value.attr2:USA
openid.ext1.type.attr3:http://axschema.org/contact/email
openid.ext1.value.attr3:mbj@microsoft.com
openid.ext1.type.attr4:http://axschema.org/contact/city/home
openid.ext1.value.attr4:Redmond
openid.ext1.type.attr5:http://axschema.org/contact/postalAddress/home
openid.ext1.value.attr5:One Microsoft Way, Building 40/5138
openid.ext1.type.attr6:http://axschema.org/namePerson/last
openid.ext1.value.attr6:Jones
openid.ext1.type.attr7:http://axschema.org/namePerson/first
openid.ext1.value.attr7:Mike
&lt;/openid:OpenIDToken&gt;</code></pre>
<p>One final technical note that will be of interest to some of you:  OpenID Information Cards do not use SAML tokens.  They use one of two variants of openid:OpenIDToken tokens (depending upon whether the OpenID relying party uses OpenID 1.1 or 2.0 authentication).</p>
<p>Go get yourself an OpenID Information Card and <a href="https://openidcards.sxip.com/">give it a spin</a>!  Read and comment on <a href="https://openidcards.sxip.com/spec/openid-infocards.html">the spec</a>.  Or even better yet, implement it and tell us about your experience!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=27</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Information Card Deployment Guide Update</title>
		<link>http://self-issued.info/?p=26</link>
		<comments>http://self-issued.info/?p=26#comments</comments>
		<pubDate>Fri, 03 Aug 2007 06:58:18 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=26</guid>
		<description><![CDATA[An updated version of the Information Card Deployment Guide is now available.  Among other improvements, it’s been updated to employ the Information Card Icon.]]></description>
			<content:encoded><![CDATA[<p><span class="plain"><img src="http://self-issued.info/images/Sign_in_with_your_Information_Card.bmp" align="right" hspace="5" alt="Sign in with your Information Card" />An updated version of the Information Card Deployment Guide is now available.  Among other improvements, it’s been updated to employ the <a href="http://self-issued.info/?p=17">Information Card Icon</a>.  As <a href="http://self-issued.info/?p=6">the original deployment guide announcement</a> said:</span></p>
<blockquote><p>So you’ve decided to use Information Cards on your web site… Now what?  I’m pleased to announce that we’ve just published a document giving step-by-step guidance to Web developers on what we believe are the best practices for doing this.  The document walks Web site developers through two different deployment scenarios: sites exclusively using Information Cards for authentication, and mixed-mode sites allowing the use of either passwords or Information Cards. Examples are given for site sign-in, site sign-up, and handling lost Information Cards, including suggested confirmation text for each of these scenarios.</p></blockquote>
<p>This link to the document <a href="http://go.microsoft.com/fwlink/?LinkId=98051">Patterns for Supporting Information Cards at Web Sites: Personal Cards for Sign up and Signing In</a> references the current version and will be updated to point to any future revisions as well.  The <a href="http://self-issued.info/?p=20">Sample Information Card Site</a> employs these guidelines and is built using the <a href="http://self-issued.info/?p=18">Information Card Relying Party Resources</a> announced earlier.  Enjoy adding Information Card support to your web sites!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=26</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Cards and CardSpace Book</title>
		<link>http://self-issued.info/?p=22</link>
		<comments>http://self-issued.info/?p=22#comments</comments>
		<pubDate>Wed, 25 Jul 2007 07:53:51 +0000</pubDate>
		<dc:creator>Mike Jones</dc:creator>
				<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Windows CardSpace]]></category>

		<guid isPermaLink="false">http://self-issued.info/?p=22</guid>
		<description><![CDATA[The first CardSpace book, <a href="http://www.marcmercuri.com/">Marc Mercuri</a>’s <a href="http://www.amazon.com/Beginning-Windows-CardSpace-Novice-Professional/dp/1590598075/ref=pd_bbs_sr_1/102-5203556-8472143?ie=UTF8&#038;s=books&#038;qid=1182879521&#038;sr=8-1">Beginning Information Cards and CardSpace: From Novice to Professional</a> went to press last week and can now be ordered.]]></description>
			<content:encoded><![CDATA[<p><img src="http://self-issued.info/images/mecuri_infocard_book_cover.jpg" align="right" alt="Beginning Information Cards and CardSpace: From Novice to Professional" />The first CardSpace book, <a href="http://www.marcmercuri.com/">Marc Mercuri</a>’s <a href="http://www.amazon.com/Beginning-Windows-CardSpace-Novice-Professional/dp/1590598075/ref=pd_bbs_sr_1/102-5203556-8472143?ie=UTF8&#038;s=books&#038;qid=1182879521&#038;sr=8-1">Beginning Information Cards and CardSpace: From Novice to Professional</a> went to press last week and can now be ordered.  Marc is an expert in CardSpace and numerous related technologies and his book is chock full of practical examples and samples.  Read more about Marc <a href="http://www.marcmercuri.com/PermaLink,guid,49803177-d57c-4580-9d80-71779e90f83f.aspx">here</a>.  Another CardSpace expert, virtual team member, and friend of mine, Steven Woodward, served as technical editor for the book.  Congratulations Marc and Steven!</p>
]]></content:encoded>
			<wfw:commentRss>http://self-issued.info/?feed=rss2&amp;p=22</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
