[OTDev] Authentication and authorisation for OpenTox REST services

Andreas Maunz andreas at maunz.de
Wed Sep 30 10:44:52 CEST 2009


Hi Nina and all,

Nina Jeliazkova wrote:
> Current status :
> 
>     * Own (minimal) implementation of AA for some services (NTUA, IDEA
>       –HTTP Basic for dataset POST, others?)
All: correct me if I am wrong, but I guess there is virtually no AA 
implemented in any individual partner service.

> Options:
> 
>     * Centralized service providing Identity
>     * Federated AA
I am in favor of a centralized service:
- could be a service (later also paid service) that we offer to the 
community.
- will be easy to maintain by a single party (Accounts are most often 
created only once and then just used).

> Technologies to consider (the list is not complete!) :
>     * HTTP Basic + SSL
>     * HTTP Digest
>     * OpenID
>     * OpenAuth
>     * Google OAuth & Federated Login  
>       http://sites.google.com/site/oauthgoog
>       <http://sites.google.com/site/oauthgoog/Overlap>
>     * FOAF + SSL (pretty new)  http://esw.w3.org/topic/foaf+ssl
>     * SAML
Personally I would give FOAF + SSL a try, due to its integration with REST.

Greetings
Andreas

-- 
http://www.maunz.de

      ERROR 666: Armageddon detected. Please restart universe and try again.



More information about the Development mailing list