<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GFIPM.net</title>
	<atom:link href="http://www.gfipm.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gfipm.net</link>
	<description>Global Federated Identity and Privilege Management</description>
	<lastBuildDate>Tue, 14 May 2013 14:02:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>GFIPM Reference Federation Updates</title>
		<link>http://www.gfipm.net/gfipm-reference-federation-updates/</link>
		<comments>http://www.gfipm.net/gfipm-reference-federation-updates/#comments</comments>
		<pubDate>Wed, 08 Aug 2012 19:16:19 +0000</pubDate>
		<dc:creator>Jeff Krug</dc:creator>
				<category><![CDATA[GFIPM]]></category>
		<category><![CDATA[Reference Federation]]></category>

		<guid isPermaLink="false">http://www.gfipm.net/?p=319</guid>
		<description><![CDATA[The GFIPM Reference Federation has continually served the GFIPM community as the primary conformance and interoperability testbed for GFIPM integration and interoperability testing efforts since 2008.  Recently the testbed was updated with a new feature to help reconcile typos and &#8230; <a href="http://www.gfipm.net/gfipm-reference-federation-updates/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The GFIPM Reference Federation has continually served the GFIPM community as the primary conformance and interoperability testbed for GFIPM integration and interoperability testing efforts since 2008.  Recently the testbed was updated with a new feature to help reconcile typos and minor attribute configuration errors on GFIPM Identity Providers.  This new capability analyzes the content of the raw SAML assertion delivered to the <a title="GFIPM Reference Service Provider" href="https://rhelsp.ref.gfipm.net" target="_blank">GFIPM Reference Service Provider</a> and verifies each attribute name and attribute name format against the <a title="GFIPM Metadata Specification" href="http://www.gfipm.net/standards/metadata/2.0/index.html" target="_blank">GFIPM Metadata Specification</a>.  In the past, when mistakes of this nature occurred it would only be detected by manual inspection of the SAML Assertion, as the reference service provider simply filtered out all invalid attributes.  Now administrators will be able to quickly see all the data they transmitted and which attributes may contain errors.</p>
<p><span id="more-319"></span></p>
<p>By using this capability along with the existing capability that analyzes attribute values for correctness against the  <a title="GFIPM Metadata Specification" href="http://www.gfipm.net/standards/metadata/2.0/index.html" target="_blank">GFIPM Metadata Specification</a>, administrators can fully validate the technical configuration of their GFIPM Identity Providers faster than ever. The following example shows how this new tool identifies incorrectly named attributes as well as attributes with incorrect name formats:</p>
<div id="attachment_326" class="wp-caption alignnone" style="width: 831px"><a href="http://www.gfipm.net/wp-content/uploads/2012/08/err.png"><img class="size-full wp-image-326" title="SAML Attribute Errors" src="http://www.gfipm.net/wp-content/uploads/2012/08/err.png" alt="" width="821" height="197" /></a><p class="wp-caption-text">This image shows an attribute name error, as well as an attribute name format error.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.gfipm.net/gfipm-reference-federation-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIEF Signing Certificate Transition Year</title>
		<link>http://www.gfipm.net/nief-signing-certificate-transition-year/</link>
		<comments>http://www.gfipm.net/nief-signing-certificate-transition-year/#comments</comments>
		<pubDate>Sat, 30 Jun 2012 16:18:29 +0000</pubDate>
		<dc:creator>Jeff Krug</dc:creator>
				<category><![CDATA[NIEF]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://www.gfipm.net/wordpress/?p=19</guid>
		<description><![CDATA[The calendar year of 2012 is a transition year for the NIEF Trust Fabric Signing Certificate.  You can read the process we are following as we migrate to a new signing certificate in the NIEF Center Root Signing Certificate Transition &#8230; <a href="http://www.gfipm.net/nief-signing-certificate-transition-year/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The calendar year of 2012 is a transition year for the NIEF Trust Fabric Signing Certificate.  You can read the process we are following as we migrate to a new signing certificate in the <a href="https://nief.gfipm.net/trust-fabric/NIEF%20Center%20Root%20Signing%20Certificate%20Transition%20Policy%20Jan%202012.pdf">NIEF Center Root Signing Certificate Transition Policy</a>.  The NIEF Trust Fabric will be signed with both certificates until February 2013, but as of August 2012 the longtime production URL at which the trust fabric was available for download will switch to being the signed with the new certificate.  This specifically will impact any organizations using SAML software that automatically downloads, validates, and uses the NIEF Trust Fabric.  Even if your organization is not using such software, I recommend being sure to update your local trust to the use the new <a href="https://nief.gfipm.net/trust-fabric/nief-ca-new.crt">NIEF Root Signing Certificate</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gfipm.net/nief-signing-certificate-transition-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
