The analyst firm's comments come after the Organisation for the
Advancement of Structured Information Standards (Oasis) approved two
key web services security components as agreed standards.
The Oasis Web Services Secure Exchange Technical Committee formally
ratified WS-SecureConversation version 1.3 for establishing and
maintaining extended secure sessions.
In addition it passed WS-Trust version 1.3, for obtaining and
exchanging security credentials.
The ratification moves web services secure messaging from basic and
limited implementation to a more extended and contextual model,
according to Gartner.
However, the real value of these standards lies in the benefits they
can provide for implementations of brokered authentication or security
token services (STS), the analyst firm believes.
Full story here:
http://www.vnu.co.uk/vnunet/news/2187007/web-services-security-finally
Shawn