30-day Public Review for SAML V2.0 Asynchronous Single Logout Profile Extension V1.0

The OASIS Security Services (SAML) TC [1] members have recently approved a Committee Specification Draft (CSD) and submitted this specification for 30-day public review:

SAML V2.0 Asynchronous Single Logout Profile Extension Version 1.0
Committee Specification Draft 01 / Public Review Draft 01
18 September 2012

Specification Overview:
This document defines an extension to the SAML 2.0 Single Logout Protocol that allows the initiator to indicate that it does not expect to receive a response from the session authority. This improves user interface interoperability in deployments that want the identity provider to control the user experience during logout.

TC Description:
The Security Services TC continues to develop value-added specifications and profiles on top of the SAML 2.0 standard, and has recently begun the process to refresh the standard to address errata and other improvements requested by the SAML community.

Public Review Period:

The public review starts today, 28 September 2012 and ends 28 October 2012.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

URIs:

The complete package of the prose specification document and related files are available in the ZIP distribution file at:

https://www.oasis-open.org/committees/download.php/47023/saml-async-slo-v1.0-csprd01.zip

Additional information about the specification and the OASIS Security Services (SAML) TC may be found at the TC’s public home page:

http://www.oasis-open.org/committees/security/

Comments may be submitted to the TC by any person through the use of the OASIS TC Comment Facility which can be located via the button labeled “Send A Comment” at the top of the TC public home, or directly at:

http://www.oasis-open.org/committees/comments/index.php?wg_abbrev=security

Comments submitted by TC non-members for this work and for other work of this TC are publicly archived and can be viewed at:

http://lists.oasis-open.org/archives/security-services-comment/

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review of SAML V2.0 Asynchronous Single Logout Profile Extension Version 1.0, we call your attention to the OASIS IPR Policy [2] applicable especially [3] to the work of this technical committee. All members of the TC should be familiar with this
document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification. OASIS invites any persons who know of any such
claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

========== Additional references:

[1] OASIS Security Services (SAML) TC
http://www.oasis-open.org/committees/security

[2] http://www.oasis-open.org/who/intellectualproperty.php

[3] http://www.oasis-open.org/committees/security/ipr.php
http://www.oasis-open.org/who/intellectualproperty.php#s10.2.3
RF on Limited Terms

Standardize cloud PaaS management API spec

Join CAMP TC before first mtg on 23 Oct

Call for Participation: OASIS Cloud Application Management for Platforms (CAMP) TC

A new OASIS technical committee is being formed. The OASIS Cloud Application Management for Platforms (CAMP) TC has been proposed by the members of OASIS listed in the charter below. The TC name, statement of purpose, scope, list of deliverables, audience, IPR mode and language specified in the proposal will constitute the TC’s official charter. Submissions of technology for consideration by the TC, and the beginning of technical discussions, may occur no sooner than the TC’s first meeting.

The eligibility requirements for becoming a participant in the TC at the first meeting are:

(a) you must be an employee or designee of an OASIS member organization or an individual member of OASIS, and

(b) you must join the Technical Committee, which members may do by using the “Join this TC” button on the TC’s home page at [a].

To be considered a voting member at the first meeting, you must:

(a) join the Technical Committee at least 7 days prior to the first meeting (on or before 16 October 2012); and

(b) you must attend the first meeting of the TC, at the time and date fixed below (23 October 2012).

Participants also may join the TC at a later time. OASIS and the TC welcomes all interested parties.

Non-OASIS members who wish to participate may contact us about joining OASIS [b]. In addition, the public may access the information resources maintained for each TC: a mail list archive, document repository and public comments facility, which will be linked from the TC’s public home page at [c].

Please feel free to forward this announcement to any other appropriate lists. OASIS is an open standards organization; we encourage your participation.

—–

[a] http://www.oasis-open.org/apps/org/workgroup/camp
[b] See http://www.oasis-open.org/join/

[c] http://www.oasis-open.org/committees/camp/

OASIS Cloud Application Management for Platforms (CAMP) Technical Committee Charter

(1) The Charter of the TC:

(1)(a) Name of the TC

OASIS Cloud Application Management for Platforms (CAMP) TC

(1)(b) Statement of purpose:

Cloud Computing is a new paradigm where applications run on shared, managed platforms and containers. Certain details may be abstracted from the users, who then no longer have need for, expertise in, or control over, the physical infrastructure.

The different types of Cloud Computing are often classified as the following (see http://csrc.nist.gov/groups/SNS/cloud-computing/ for more complete definitions of these terms) although other flavors of Cloud Computing are possible.

* Software as a Service (SaaS), where users interact with the applications directly
* Platform as a Service (PaaS), where users manage the platform that applications are hosted on
* Infrastructure as a Service (IaaS), where users manage virtual machine instances with stacks of middleware supporting applications

The purpose of this TC is to define models, mechanisms and protocols for the management of applications in, and their use of, a Platform as a Service (PaaS) environment.

The focus of this TC is to develop an interoperable protocol for PaaS (self service) management interfaces for cloud users to use in developing, deploying and the administration of their applications. PaaS management should allow for, but not require, IaaS management to manage the deployment of resources for an application. If an IaaS infrastructure is used as an underlying, enabling technology, the IaaS API should not show through to the PaaS management interface.

The TC will define interfaces for self-service provisioning, monitoring and control. A standard interface for PaaS application management is expected to enable an ecosystem consisting of common tools, plugins, libraries and frameworks, which would remedy the current situation of bespoke interfaces for different vendor platforms that do not provide much vendor value-add.

(1)(c) Scope of work

The TC will accept as input the CAMP V1.0 Specification published on 29th August 2012:

http://www.cloudspecs.org/CAMP/CAMP_v1-0.pdf

which can be found at

http://www.cloudspecs.org

The TC will refine this initial contribution to produce an OASIS Standard specification, including necessary supporting documentation in the form of Committee Notes.

Other contributions will be accepted for consideration without any prejudice or restrictions and evaluated based on technical merit in so far as they conform to this charter. Members with extensive experience and knowledge in these areas are particularly invited to participate.

The scope of the TC’s work includes the following features and capabilities:

* Facilities to compose application assemblies from custom components as well as application-level services provided by the platform. Assemblies will run on a cloud PaaS platform.
* Allow components to be imported from libraries/repositories. Manage libraries/repositories
* Configure components and assemblies
* Register/deregister/start/stop/hibernate/snapshot assemblies
* Allow patching and versioning of applications and components
* Monitor components and assemblies for performance and failure
* Allow introspection of components and assemblies to discover capabilities and customization points.
* Provide facilities to keep track of usage for metering and billing
* Describe a platform-packaging format for applications and components that will allow portability across platforms, and allow framework-specific and/or language-specific extensions for transporting and deploying the application code.
* Allow for development of applications either in a standalone Application Development Environment (ADE) or as part of the platform offering.
* Definition and/or development of facilities and artifacts to support testing, such as test assertions, test scenarios and test suites, as the TC decides is appropriate.
* Define management interfaces for common, widely available platform services. The interface that these platform services offer to the application for the service’s
primary function (e.g. database search interface) is specifically out of scope.
To further clarify this point an example follows:
** The definition of management interfaces for a messaging service (e.g. Platform Components and Platform Component Templates that represent a messaging service).

This scope is further detailed by the input contribution.

Out of Scope

The following is a non-exhaustive list provided only for the sake of clarity.

The following items are specifically out of scope of the work of the TC:

* Definition of any application-level Cloud services (SaaS)
* Definition of any non-management interfaces to platform services including those used by the application to access the primary function of the service (such as posting a message to a message service bus).
To further clarify this point an example follows:
** The definition of a functional interface to a messaging service (e.g. a Ruby API for interacting with a messaging service using AMQP).

* Facilities and interfaces that are programming language-specific and/or platform-specific (e.g. .Net, Java EE).
* Mechanisms and interfaces to manage infrastructure resources (IaaS), although hooks to such interfaces may be defined.

Testing

Testing of the specification shall be performed in periodic plug fests.

(1)(d) A list of deliverables

The TC has the following set of deliverables:

* A Platform Management architecture and interface specification that includes a model for managing the lifecycle of applications and a protocol binding defined using REST and JSON. This is to be completed within 18 months after the initial TC meeting.
* For all deliverables, the group shall define concrete exit criteria as early as possible. The exit criteria must be met before the deliverable advances to Committee Specification. At a minimum, at least two interoperating implementations of both clients and servers must be available that test the mandatory and optional features of the specification. (Note: optional features may be tested by different implementations that implement different set of optional features (in addition to the mandatory features) as long as pairwise coverage for each optional feature is covered. Each client and each server must be from different respective code bases.

In order to achieve the 18-month deadline of the main deliverable, testing shall start within 6 months of the start of the TC.

Optionally, other relevant non-standards track deliverables, such as tutorials and primers.

Maintenance

The TC will engage in Maintenance Activities with respect to the OASIS Final Deliverables it produces.

The TC will collect issues raised against the deliverables and periodically process those issues. Issues that request or require new or enhanced functionality shall be marked as
enhancement requests and set aside. Issues that result in the clarification or correction of the deliverables shall be processed as part of that deliverable’s Maintenance Activity The group shall maintain a list of these adopted clarifications and shall periodically and at least once a year create a new OASIS Final Deliverable including these updates.

(1)(e) IPR Mode

The TC will operate under the Non Assertion IPR mode as defined in the OASIS Intellectual Property Rights (IPR) Policy effective 15 October 2010.

(1)(f) Anticipated Audience

The anticipated audience for this work includes:

* Vendors offering products designed to support cloud applications in a PaaS environment.
* Software architects and programmers, who design, write, integrate and deploy cloud applications using a PaaS architecture.
* Policy administrators who create and govern policy for services and applications in a PaaS environment.
* Vendors making products used to integrate applications and services (both hardware and software), such as ESBs.

(1)(g) Language

TC business will be conducted in English. The output documents will be written in English.

(2) Non-normative information regarding the startup of the TC

(2)(a) Similar or Applicable Work

1. CAMP adopts Representational State Transfer (REST) principles for exposing and consuming resources services over Hypertext Transfer Protocol (HTTP) based systems. JSON is used for defining formats for representing data to/from the resources.

2. The DMTF Cloud Management Working Group is finishing up work on standardizing the model and interfaces for managing IaaS facilities in the Cloud [1].

3. The Open Grid Forum has produced a specification called Open Cloud Computing Interface [2], also for managing IaaS.

4. The Storage Networking Industry Association SNIA has produced the Cloud Data Management Interface (CDMI) [3], and has submitted it to JTC 1 for ISO standardization.

5. OASIS has an Identity in the Cloud Technical Committee [4] and recently started the OASIS Topology and Orchestration Specification for Cloud Applications (TOSCA) TC [5].

6. There is also a DMTF standard called Open Virtualization Format for packaging and distributing virtual appliances, or more generally software stacks, to be run in virtual machines [6].

7. The Open Data Center Alliance has recently published OCDA Usage Model: Platform as a Service (Paas) Interoperability Rev 1.0 [8]

8. A more complete list of cloud standards activities can be found on the Cloud Standards Wiki [7].

(2)(b) Date, Time, and Location of First Meeting

The first meeting of the CAMP TC will be a teleconference to be held on Tuesday 23rd October 2012, 8am to 9:30am Pacific Time. This teleconference will be sponsored by Oracle. A face-to-face meeting has been scheduled for Tuesday through Thursday 06-08 November, 2012 in the San Francisco Bay area.

(2)(c) On-Going Meeting Plans & Sponsors

It is anticipated that the CAMP TC will meet via teleconference every week for 90 minutes at a time determined by the TC members during the TC’s first meeting. It is anticipated that the CAMP TC will meet face-to-face every 3-4 months at a time and location to be determined by the TC members. TC members will determine the actual pace of face-to-face and teleconference meetings. One of the proposers, as listed below, will sponsor the teleconferences unless other TC members offer to donate their own facilities.

(2)(d) Proposers of the TC

Mark Carlson, mark.carlson@oracle.com, Oracle

Siddhartha Chandurkar, siddhartha.chandurkar@shephertz.com, ShepHertz

Martin Chapman, martin.chapman@oracle.com, Oracle

Alex Heneveld, alex.heneveld@cloudsoftcorp.com, Cloudsoft

Scott Hinkelman, scott.hinkelman@oracle.com, Oracle

David Jilk, dave.jilk@standingcloud.com, Standing Cloud

Duncan Johnston-Watt, duncan.johnstonwatt@cloudsoftcorp.com, Cloudsoft

Anish Karmarkar, anish.karmarkar@oracle.com, Oracle

Tobias Kunze, tkunze@redhat.com, Red Hat

Ashok Malhotra, ashok.malhotra@oracle.com, Oracle

Jeff Mischkinsky, jeff.mischkinsky@oracle.com, Oracle

Adrian Otto, adrian.otto@rackspace.com, Rackspace

Gilbert Pilz, gilbert.pilz@oracle.com, Oracle

David Sawyer, david.sawyer@jumpsoft.net, JumpSoft

Zhexuan Song, Zhexuan.Song@huawei.com, Huawei

Prasad Yendluri, Prasad.Yendluri@softwareag.com, Software AG

(2)(e) Statements of Support

Martin Chapman, martin.chapman@oracle.com, Oracle: As Oracle’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all Oracle proposers listed in (2)(d).

Siddhartha Chandurkar, siddhartha.chandurkar@shephertz.com, ShepHertz Technologies Pvt. Ltd.: As ShepHertz’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all ShepHertz proposers listed in (2)(d).

David Jilk, dave.jilk@standingcloud.com, Standing Cloud: As Standing Cloud’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all Standing Cloud proposers listed in (2)(d).

Duncan Johnston-Watt, duncan.johnstonwatt@cloudsoftcorp.com, CloudSoft: As Cloudsoft’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all Cloudsoft proposers listed in (2)(d).

Mark Little, mlittle@redhat.com, Red Hat: As Red Hat’s representative to OASIS, I approve the CAMP TC Charter, and endorse all Red Hat proposers listed in (2) (d).

Adrian Otto, adrian.otto@rackspace.com, Rackspace: As Rackspace’s representative to OASIS, I approve the CAMP TC Charter, and endorse all Rackspace proposers listed in (2) (d).

David Sawyer, david.sawyer@jumpsoft.net, JumpSoft: As JumpSoft’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all JumpSoft proposers listed in (2)(d).

Zhexuan Song, zhexuan.song@huawei.com, Huawei: As Huawei’s Primary Representative to OASIS, I approve the CAMP TC Charter, and endorse all Huawei proposers listed in (2)(d).

Prasad Yendluri, Prasad.Yendluri@softwareag.com, Software AG: As Software AG’s primary representative to OASIS, I approve the CAMP TC Charter, and endorse all our proposers listed in (2) (d).

(2)(f) TC Convener

Jeff Mischkinsky, jeff.mischkinsky@oracle.com, Oracle, will be the Convener of the CAMP TC.

(2)(g) Affiliation to Member Section

None

(2)(h) Initial Contribution

CAMP v1.0, 29th August 2012, http://www.cloudspecs.org/CAMP/CAMP_v1-0.pdf

(2)(i) Draft Frequently Asked Questions (FAQ) (optional)

N/A

(2)(j) Working title and acronym for the Work Products to be developed by the TC

Cloud Application Management for Platforms specification (CAMP)

References

[1] DMTF Cloud Infrastructure Management Interface: http://www.dmtf.org/cloud

[2] Open Cloud Computing Interface – Core: http://www.ogf.org/documents/GFD.183.pdf & Infrastructure: http://www.ogf.org/documents/GFD.184.pdf

[3] SNIA Cloud Data Management Interface (CDMI): http://www.snia.org/cloud

[4] OASIS Identity in the Cloud TC: http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=id-cloud

[5] OASIS Topology and Orchestration Specification for Cloud Applications (TOSCA) : http://www.oasis-open.org/committees/tosca

[6] DMTF OVF Specification V1.1.0 (ISO standard): http://www.dmtf.org/sites/default/files/standards/documents/DSP0243_1.1.0.pdf

[7] ODCA Usage Model: Platform as a Service (PaaS) Interoperability Rev 1.0 http://www.opendatacenteralliance.org/docs/ODCA_PAAS_Interop_UM_Rev1.0_BD.pdf

[8] Cloud Standards Wiki: http://cloud-standards.org/wiki/index.php

Read latest issue of OASIS News: 18 Sept

Bimonthly summary of announcements & deadlines

New book: CMIS and Apache Chemistry in Action

by Florian Müller, Jay Brown, and Jeff Potts

30-day Public Review for Reference Architecture Foundation for SOA v1.0

The OASIS Service Oriented Architecture Reference Model TC members [1] have produced an updated Committee Specification Draft (CSD) and submitted this specification for 30-day public review:

Reference Architecture Foundation for Service Oriented Architecture Version 1.0
Committee Specification Draft 04 / Public Review Draft 03
01 August 2012

Specification Overview:
This document specifies the OASIS Reference Architecture Foundation for Service Oriented Architecture (SOA-RAF). It follows from the concepts and relationships defined in the OASIS Reference Model for Service Oriented Architecture as well as work conducted in other organizations. While it remains abstract in nature, the current document describes the foundation upon which specific SOA concrete architectures can be built.

The focus of the SOA-RAF is on an approach to integrating business with the information technology needed to support it. These issues are always present but are all the more important when business integration involves crossing ownership boundaries.

The SOA-RAF follows the recommended practice of describing architecture in terms of models, views, and viewpoints, as prescribed in the ANSI/IEEE 1471-2000 (now ISO/IEC 42010-2007) Standard.

It has three main views: the Participation in a SOA Ecosystem view which focuses on the way that participants are part of a Service Oriented Architecture ecosystem; the Realization of a SOA Ecosystem view which addresses the requirements for constructing a SOA-based system in a SOA ecosystem; and the Ownership in a SOA Ecosystem view which focuses on what is meant to own a SOA-based system.

The SOA-RAF is of value to Enterprise Architects, Business and IT Architects as well as CIOs and other senior executives involved in strategic business and IT planning.

Public Review Period:
The public review starts 14 September 2012 and ends 14 October 2014.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

URIs:
The complete package of the prose specification document and related files are available in the ZIP distribution file at:

https://www.oasis-open.org/committees/download.php/46922/soa-ra-v1.0-csprd03.zip

Additional information about the specification and the OASIS OASIS Service Oriented Architecture Reference Model TC may be found at the TC’s public home page located at:

http://www.oasis-open.org/committees/soa-rm/

Comments may be submitted to the TC by any person through the use of the OASIS TC Comment Facility which can be accessed via the button labeled “Send A Comment” at the top of the TC public home page, or directly at:

http://www.oasis-open.org/committees/comments/form.php?wg_abbrev=soa-rm

Feedback submitted by TC non-members for this work and for other work of this TC is publicly archived and can be viewed at:

http://lists.oasis-open.org/archives/soa-rm-comment/

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review of Reference Architecture Foundation for Service Oriented Architecture Version 1.0, we call your attention to the OASIS IPR Policy [2] applicable especially [3] to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

========== Additional references:

[1] OASIS Service Oriented Architecture Reference Model TC
http://www.oasis-open.org/committees/soa-rm/

[2] http://www.oasis-open.org/who/intellectualproperty.php

[4] http://www.oasis-open.org/committees/soa-rm/ipr.php
RF on Limited mode
https://www.oasis-open.org/policies-guidelines/ipr#s10.2.3

International Cloud Symposium to Address Public Policy and Standards for Security in the Cloud

13 September 2012 – The unique security challenges faced by the public sector in deploying cloud computing will be the focus of the International Cloud Symposium (ICS), the second in a series of events hosted by the not-for-profit OASIS open standards consortium. High-level government officials from around the world will explore the intersection of policies, standards, and best practices with leaders from the privacy, identity, and security industry. ICS will be held on 10-12 October in the Washington, DC area. https://www.oasis-open.org/events/cloud/2012

“Public and governmental institutions use a big volume of confidential or sensitive data such as citizen personal information. The privacy and protection of this data are top concerns for them, particularly in the EU,” said Adil Soussi Nachit of the Belgium Ministry of Finance. “Organizations willing to go to the Cloud should have clear data governance and identify the risks especially when the Cloud provider has datacenters in multiple jurisdictions.”

Responses to the need for policy and standards in the Cloud have been driven to a great degree on a national basis. ICS will work to broaden the dialogue with presentations from key players in Europe, North America, and Asia. The event will offer a truly global perspective of the standardization issues for Cloud security.

“Cloud computing is built on standards, and standards are a core issue for ensuring that interoperable systems can be configured to meet both business requirements and the demands of international laws and regulations,” said Paul Lipton, VP Industry Standards and Open Source at CA Technologies, OASIS Board Director, and Co-Chair of the OASIS TOSCA Technical Committee. “Even as public sector policymakers are beginning to look closely at the cloud, in OASIS we are building standards that will help strengthen the policy-configurable security, privacy, and portability of cloud applications.”

ICS Sponsors:

  • CA Technologies
  • IBM
  • Microsoft

U.S. Government Speakers:

  • Dawn Leaf, Department of Commerce
  • Anil Karmel, Department of Energy, National Nuclear Security Administration
  • Deb Gallagher, General Services Administration
  • Lisa Carnahan, National Institute of Standards & Technology…

Other Speakers represent:

  • Amazon Web Services
  • American National Standards Institute (ANSI)
  • Bank of America
  • Carnegie Mellon University
  • CA Technologies
  • European Commission
  • IBM US Federal Business
  • KuppingerCole
  • Microsoft Federal Civilian Business
  • Oracle Public Sector
  • Salesforce
  • and many more organizations…

ICS supporters include the Siena Initiative (funded by the European Union), the Cloud Standards Customer Council, the Cloud Computing Best Practices Network, the U.S. National Institute of Standards and Technology (NIST), and the European Association for e-Identity and Security (eema).

Registration for this event is open to all, but space is limited, so early registration is advised.

Press passes are available; contact communications@oasis-open.org.

About OASIS
OASIS is a not-for-profit, international consortium that drives the development, convergence and adoption of open standards for the global information society. OASIS promotes industry consensus and produces worldwide standards for cloud computing, security, business transactions, electronic publishing, Smart Grid, and other applications. OASIS open standards offer the potential to lower cost, stimulate innovation, grow global markets, and protect the right of free choice of technology. OASIS members broadly represent the marketplace of public and private sector technology leaders, users and influencers. The consortium has more than 5,000 participants representing over 600 organizations and individual members in 100 countries. http://www.oasis-open.org.

Contact: communications@oasis-open.org

15-day Public Review for WS-HumanTask v1.1

The OASIS WS-BPEL Extension for People (BPEL4People) TC members [1] have produced an updated Committee Specification Draft (CSD) and submitted this specification for 15-day public review:

Web Services Human Task (WS-HumanTask) Specification Version 1.1
Committee Specification Draft 12 / Public Review Draft 05
24 July 2012

Specification Overview:
The BPEL4People TC has fixed a number of reported defects in the WS-HumanTask V1.1 Committee Specification.

TC Description:
The BPEL4People meets periodically to address any defects reported against the BPEL4People and WS-HumanTask Committee Specifications.

Public Review Period:
The public review starts 11 September 2012 and ends 26 September 2012. The specification was previously submitted for public review [2]. This 15-day review is limited in scope to changes made from the previous review. Changes are highlighted in the diff-marked PDF file included in the release package.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

URIs:
The complete package of the prose specification document and related files are available in the ZIP distribution file at:

http://www.oasis-open.org/committees/download.php/46869/ws-humantask-v1.1-csprd05.zip

Additional information about the specification and the OASIS WS-BPEL Extension for People (BPEL4People) TC may be found at the TC’s public home page located at:

http://www.oasis-open.org/committees/bpel4people/

Comments may be submitted to the TC by any person through the use of the OASIS TC Comment Facility which can be accessed via the button labeled “Send A Comment” at the top of the TC public home page, or directly at:

http://www.oasis-open.org/committees/comments/form.php?wg_abbrev=bpel4people

Feedback submitted by TC non-members for this work and for other work of this TC is publicly archived and can be viewed at:

http://lists.oasis-open.org/archives/bpel4people-comment/

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review of Web Services Human Task (WS-HumanTask) Specification Version 1.1, we call your attention to the OASIS IPR Policy [3] applicable especially [4] to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

========== Additional references:

[1] OASIS WS-BPEL Extension for People (BPEL4People) TC
http://www.oasis-open.org/committees/bpel4people/

[2] Public Reviews:
15-day public review, 18 May 2010: http://lists.oasis-open.org/archives/tc-announce/201005/msg00005.html
60-day public review, 15 December 2009: http://lists.oasis-open.org/archives/tc-announce/200912/msg00001.html

[3] http://www.oasis-open.org/who/intellectualproperty.php

[4] http://www.oasis-open.org/committees/bpel4people/ipr.php
RF on Limited mode
https://www.oasis-open.org/policies-guidelines/ipr#s10.2.3

30-day Public Review for CMIS v1.1

The OASIS Content Management Interoperability Services (CMIS) TC [1] members have recently approved a Committee Specification Draft (CSD) and submitted this specification for 30-day public review:

Content Management Interoperability Services (CMIS) Version 1.1
Committee Specification Draft 01 / Public Review Draft 01
18 August 2012

Specification Overview:
The Content Management Interoperability Services (CMIS) standard defines an interface that can be used by applications to work with one or more Content Management repositories/systems. The interface is designed to be layered on top of existing Content Management systems and their existing programmatic interfaces.

Version 1.0 of CMIS defines a domain model, plus Web Services and Restful AtomPub protocol bindings. Version 1.1 adds a browser (JSON) binding as well as type mutability, secondary object type, retention and hold support, and other features.

TC Description:
The Content Management Interoperability Services (CMIS) TC develops interoperability standard for content management repositories/systems. It also conducts interoperability testing of its draft specification among TC members periodically.

Public Review Period:

The public review starts today, 10 September 2012 and ends 10 October 2012.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

URIs:

The prose specification document and related files are available here:

PDF (Authoritative):
http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/CMIS-v1.1-csprd01.pdf

HTML:
http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/CMIS-v1.1-csprd01.html

Editable source (Note editable source files are in TeX):
http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/tex/CMIS-v1.1-csprd01-source.zip

Other specification artifacts:
XML schemas, WSDL and Orderly schema:
http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/schema/

XML and JSON examples:
http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/examples/

ZIP distribution file (complete):
For your convenience, OASIS provides a complete package of the prose specification and related files in a ZIP distribution file. You can download the ZIP file here:

http://docs.oasis-open.org/cmis/CMIS/v1.1/csprd01/CMIS-v1.1-csprd01.zip

Additional information about the specification and the Content Management Interoperability Services (CMIS) TC may be found at the TC’s public home page:

http://www.oasis-open.org/committees/cmis/

Comments may be submitted to the TC by any person through the use of the OASIS TC Comment Facility which can be located via the button labeled “Send A Comment” at the top of the TC public home, or directly at:

https://www.oasis-open.org/committees/join

Comments submitted by TC non-members for this work and for other work of this TC are publicly archived and can be viewed at:

https://lists.oasis-open.org/archives/cmis-comment/

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review of Content Management Interoperability Services (CMIS) Version 1.1, we call your attention to the OASIS IPR Policy [2] applicable especially [3] to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

========== Additional references:

[1] OASIS Content Management Interoperability Services (CMIS) TC
http://www.oasis-open.org/committees/cmis/

[2] http://www.oasis-open.org/who/intellectualproperty.php

[3] http://www.oasis-open.org/committees/cmis/ipr.php
RF on RAND mode
https://www.oasis-open.org/policies-guidelines/ipr#s10.2.2

Register for SAML webinar, 25 Sept

Learn about SAML 2.1

Committee Specifications & Committee Notes published by the Key Management Interoperability Protocol (KMIP) TC

We are pleased to announce the approval and publication of two OASIS Committee Specifications and two Committee Notes by the members of the OASIS Key Management Interoperability Protocol (KMIP) TC [1]:

Key Management Interoperability Protocol Specification Version 1.1
Committee Specification 01
27 July 2012

Key Management Interoperability Protocol Profiles Version 1.1
Committee Specification 01
27 July 2012

Key Management Interoperability Protocol Usage Guide Version 1.1
Committee Note 01
27 July 2012

Key Management Interoperability Protocol Test Cases Version 1.1
Committee Note 01
27 July 2012

Overview:

The Key Management Interoperability Protocol (KMIP) is a single, comprehensive protocol for communication between clients that request any of a wide range of encryption keys and servers that store and manage those keys. By replacing redundant, incompatible key management protocols, KMIP provides better data security while at the same time reducing expenditures on multiple products.

Key Management Interoperability Protocol is intended for developers and architects who wish to design systems and applications that interoperate using the Key Management Interoperability Protocol Specification.

Key Management Interoperability Protocol V1.1 enhances the KMIP V1.0 standard (established in October 2010) by

1) defining new functionality in the protocol to improve interoperability, such as a Discover Versions operation and a Group object;
2) defining additional Test Cases for verifying and validating the new functionality;
3) providing additional information in the KMIP Usage Guide to assist in effective implementation of KMIP in key management clients and servers; and
4) defining new profiles for establishing KMIP-compliant implementations.

URIs:
The prose specification documents and related files are available here:

* Key Management Interoperability Protocol Specification Version 1.1
Editable source:
http://docs.oasis-open.org/kmip/spec/v1.1/cs01/kmip-spec-v1.1-cs01.doc

HTML:
http://docs.oasis-open.org/kmip/spec/v1.1/cs01/kmip-spec-v1.1-cs01.html

PDF:
http://docs.oasis-open.org/kmip/spec/v1.1/cs01/kmip-spec-v1.1-cs01.pdf

* Key Management Interoperability Protocol Profiles Version 1.1
Editable source:
http://docs.oasis-open.org/kmip/profiles/v1.1/cs01/kmip-profiles-v1.1-cs01.doc

HTML:
http://docs.oasis-open.org/kmip/profiles/v1.1/cs01/kmip-profiles-v1.1-cs01.html

PDF:
http://docs.oasis-open.org/kmip/profiles/v1.1/cs01/kmip-profiles-v1.1-cs01.pdf

* Key Management Interoperability Protocol Usage Guide Version 1.1
Editable source:
http://docs.oasis-open.org/kmip/ug/v1.1/cn01/kmip-ug-v1.1-cn01.doc

HTML:
http://docs.oasis-open.org/kmip/ug/v1.1/cn01/kmip-ug-v1.1-cn01.html

PDF:
http://docs.oasis-open.org/kmip/ug/v1.1/cn01/kmip-ug-v1.1-cn01.pdf

* Key Management Interoperability Protocol Test Cases Version 1.1
Editable source:
http://docs.oasis-open.org/kmip/testcases/v1.1/cn01/kmip-testcases-v1.1-cn01.doc

HTML:
http://docs.oasis-open.org/kmip/testcases/v1.1/cn01/kmip-testcases-v1.1-cn01.html

PDF:
http://docs.oasis-open.org/kmip/testcases/v1.1/cn01/kmip-testcases-v1.1-cn01.pdf

Distribution ZIP files
For your convenience, OASIS provides a complete package of each specification and note in a ZIP distribution file. You can download the ZIP files here:

* Key Management Interoperability Protocol Specification Version 1.1
http://docs.oasis-open.org/kmip/spec/v1.1/cs01/kmip-spec-v1.1-cs01.zip

* Key Management Interoperability Protocol Profiles Version 1.1
http://docs.oasis-open.org/kmip/profiles/v1.1/cs01/kmip-profiles-v1.1-cs01.zip

* Key Management Interoperability Protocol Usage Guide Version 1.1
http://docs.oasis-open.org/kmip/ug/v1.1/cn01/kmip-ug-v1.1-cn01.zip

* Key Management Interoperability Protocol Test Cases Version 1.1
http://docs.oasis-open.org/kmip/testcases/v1.1/cn01/kmip-testcases-v1.1-cn01.zip

Members of the KMIP TC requested Special Majority Votes to approve their committee drafts as a Committee Specifications and Committee Notes. The committee drafts had been released for public review as required by the TC Process [2]. The votes passed [3], and the approved documents are now available online in the OASIS Library as referenced above.

Our congratulations to the TC on achieving this milestone.

========== Additional references:

[1] OASIS Key Management Interoperability Protocol (KMIP) TC
http://www.oasis-open.org/committees/kmip/

[2] Public reviews
15-day public review, 1 June 2012: https://lists.oasis-open.org/archives/tc-announce/201206/msg00000.html
30-day public review, 22 January 2012: https://lists.oasis-open.org/archives/tc-announce/201201/msg00009.html

[3] CS ballots

* Key Management Interoperability Protocol Specification Version 1.1: https://www.oasis-open.org/committees/ballot.php?id=2261

* Key Management Interoperability Protocol Profiles Version 1.1: https://www.oasis-open.org/committees/ballot.php?id=2262

* Key Management Interoperability Protocol Usage Guide Version 1.1: https://www.oasis-open.org/committees/ballot.php?id=2263

* Key Management Interoperability Protocol Test Cases Version 1.1: https://www.oasis-open.org/apps/org/workgroup/kmip/ballot.php?id=2264

Read latest issue of OASIS News: 5 Sept

Bimonthly summary of announcements & deadlines

No results with the selected filters