Changes include the following:
SSL certi?¬?cates. Used to allow relying parties to identify
themselves. Extended Validation (EV) SSL certi?¬?cates
raise the bar with greater scrutiny, additional checks, and
a guarantee from the certifying authority.
Cryptography. Not only the foundation for HTTPS, but
the encryption and digital signatures that are part of
WS-*.
WS-*. Speci?¬?cations providing interoperable protocols
for security, reliable messaging, and transactions in
loosely coupled systems. For RPs, the pieces of WS-*
required are small; at a minimum, Extended Markup
Deciding to Be a Relying Party
Adopting support
for Information
Cards requires
changes at the
server
272 Guidance for a Relying Party
Language (XML) Signature and XML Encryption are required
to accept tokens via a POST from the browser
over Secure HyperText Transfer Protocol (HTTPS).
Increasing awareness around privacy. Greater concerns
around data security and privacy are encouraging RPs to
reevaluate the types of information they request and
store about their users. Limiting the types of identifying
information and private data about users decreases potential
legal liabilities in the event of a breach.
Pages:
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403