<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Adventures of an Eternal Optimist &#187; federated provisioining</title>
	<atom:link href="http://eternallyoptimistic.com/tag/federated-provisioining/feed/" rel="self" type="application/rss+xml" />
	<link>http://eternallyoptimistic.com</link>
	<description></description>
	<lastBuildDate>Fri, 10 Feb 2012 18:56:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Silo Sync vs. Service Sync</title>
		<link>http://eternallyoptimistic.com/2009/02/08/silo-sync-vs-service-sync/</link>
		<comments>http://eternallyoptimistic.com/2009/02/08/silo-sync-vs-service-sync/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 18:38:30 +0000</pubDate>
		<dc:creator>Pamela</dc:creator>
				<category><![CDATA[Provisioning]]></category>
		<category><![CDATA[federated provisioining]]></category>

		<guid isPermaLink="false">http://eternallyoptimistic.com/?p=901</guid>
		<description><![CDATA[Aha!  More fodder for discussion: &#8230;the identity information needs to be synchronized before the user performs his first authentication. Why?   Why must identity information be synchronized before the user performs the first authentication?  If a new employee has been provisioned an account at an IdP,  why shouldn&#8217;t that person be able to arrive at a [...]]]></description>
			<content:encoded><![CDATA[<p>Aha!  More fodder for discussion:</p>
<p><a href="http://idlogger.wordpress.com/2009/02/07/janus-versus-vulcan-in-federated-provisioning/" target="_blank">&#8230;the identity information needs to be synchronized before the user performs his first authentication</a>.</p>
<p>Why?   Why must identity information be synchronized before the user performs the first authentication?  If a new employee has been provisioned an account at an IdP,  why shouldn&#8217;t that person be able to arrive at a Relying Party, and at that time have the IdP advise the Relying Party that (1) the user is valid, and (2) the user should be provisioned into the system?     I don&#8217;t see why my example from earlier can&#8217;t work in reverse &#8212; you batch update your incoming staff updates, but if they attempt to access the system before the batch job is accomplished, the IdP bundles a specific real-time provisioning request into the authentication, and the user is set up and granted access.</p>
<p>To me, real-time back-end data synchronization is needed between silos.  Once you have a single Identity authority with a reach across administrative domains, and once you are doing more than testing possession of a shared secret, you have alternatives.  Perhaps not in every case &#8211; but in some cases, perhaps many cases.  Imaginative exploration of these new usage models are what makes this technology so much fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://eternallyoptimistic.com/2009/02/08/silo-sync-vs-service-sync/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

