Tuesday, November 4, 2008

Using an XML Gateway as a Federation Gateway, with an STS

Vordel's XML Gateway operates as a Security Token Service (STS), which means it can be used as a Federation Gateway in a scenario like the example shown below. In the case below, using SiteMinder, the XML Gateway at site 2 (on the right) consumes SAML tokens (v1.0, v1.1, or v2), maps them to the local identity at site 2, and then binds the clients message to an existing or new SiteMinder session. This means that the client can access a Web Service at site 2 as if they'd logged in there. The XML Gateway and STS infrastructure enables this.

Because the Vordel XML Gateway includes STS support out-of-the-box, the STS part of the architecture is provided by the XML Gateway. A Vordel customer does not have to go out to the market in order to buy an STS.



If we focus on the STS part of the solution, we see that it can be used not only for Active Directory, but for Sun Access Manager, CA SiteMinder, Tivoli Access Manager, and others. The value of an STS is a number of the amount of identity infrastructure it plugs into multiplied by the number of security tokens it supports.