ABSTRACT

For access control, the required credential is the SAML Token, which is constructed at runtime by an STS that has access to a claims store in an EAS. e SAML may also be created by a trusted federation partner in accordance with federation agreements. In each case, the SAML is provided directly to the service provider after authentication. A software handler, provided by the enterprise as a Java or .NET executable, may be compiled into the software of the web service or web application. is handler (or appliqué) veries and validates the SAML and extracts the claims.