Recap 8/25/2005
- POC Use Case approved pending changes to the
Get/Build/Deploy service. Changes made and posted.
- Events raised from within a service flow should have a
reference id pointing back to the event that kicked off the service flow. This
will allow auditors to follow the chain of events.
- Support for an identity server should not be part of the
ALF specification. This support can be added through the use of a Service Provider Interface (SPI). Shaw suggests our sample implementation use the SPI
to implement JOSSO or something similar.
New Business: roles in ALF. (I suspect this subject
will easily take up the remaining time.) Secure
Software has expertise in this area and will be leading the meeting.
- What is the purpose of roles in ALF?
- How
will ALF roles be supported by the individual tools?
- How
do ALF roles tie to permissions?
- Other role questions...