FO FED DEATED IDENTITY ELEASE NOTES ELEASE 3.2 April 18, 2012
FO FEDEATED IDENTITY ELEASE NOTES Cpyright Infrmatin The infrmatin cntained herein is the cnfidential and prprietary prperty f IP Cmmerce, Inc. and may nt be used, distributed, mdified, disclsed, r reprduced withut the express written permissin f IP Cmmerce, Inc., Inc. Cpyright 2012 IP Cmmerce, Inc., Inc. All rights reserved. The symbl http://www.ipcmmerce.cm. and the initials IPC are registeredd trademarks f IP Cmmerce, Inc.
FO FEDEATED IDENTITY ELEASE NOTES T TABLE OF CONTENC NTS eleasee Ntes... 1 New in elease... 1 General... 1 Tken Sign-On Service... 1 Fixed in elease... 2 Identity Authrity Service... 2 elying Service... 2 Knwnn Issues in elease... 2 Additinal esurces... 2 Online Dcumentatin... 2 TABLE OF CONTENTS - I
FO FEDEATED IDENTITY ELEASE NOTES ELEASE NOTES The SSO API fr Federated Identity 3.2 elease Ntes includes the fllwing sectins: New in elease Fixed in elease Knwn Issues in elease Additinal esurces New in elease The fllwing sectin prvides infrmatin abut new functinality added t the SSO API fr Federated Identity fr bth SOAP and EST implementatins fr elease 3.2. General A new service called the Tken Sign-On Service has been created that allws external sftware systems t initiate sign-n authenticatin n requests t ne r mre IPC-managed security dmains by presenting an identity tken (strng authenticatin) ) r an pen secret (pen authenticatin). Fr mre infrmatin, refer t Integratin Guidance: Public Sign-On in the SSO API fr Federated Identity guide n CmmerceDcs. Supprt fr single-use tken artifacts has been added. Fr mre infrmatin, refer t Understanding Artifacts in the SSO API fr Federated Identity guide n CmmerceDcs. Tken Sign-On Service The fllwing Tken Sign-On Service peratins havee been addedd t supprt bth pen and strng sign-n authenticatin: SignOn() Supprts strng authenticatin based n the issuance f identity tkens which are passed with each sign-n authenticatin request t initiate the return f a sessin tken used fr all subsequent transactin requests. OpenSignOn() Supprts pen authenticatin using an "pen secret" intended fr mbile applicatin develpment scenaris where authenticatin credentials will be distributed acrss a large number f mbile devices where the prtectin f embedded credentials cannt be ensured. ELEASE NOTE ES - 1
FO FEDEATED IDENTITY ELEASE NOTES The fllwing advanced peratins have als been added: OpenSignOnTSecurityDmains() Used t perfrm pen authenticatin using a shared secret t receivee a sessin tken artifact fr the specified security dmain(s). SignOnTSecurityDmains() Used t perfrm strng authenticatin using identity tkens t receive a sessin tken assciated withh the first dmain specified in a list f security dmain names. Fixed in elease The fllwing sectins prvide infrmatin abut items that were fixed in the SSO API fr Federated Identity fr bth SOAP and EST implementatins fr elease 3.2. Identity Authrity Service A fix has been applied that prevents duplicate ClaimNs values when invking the CreateStaticClaims() peratin and then the CreateSecurityDmainClaim() peratin within the same security dmain. elying Service A fix has been applied that allws the value f a cnfidential static claim t exceed 150 characters. Prir t this fix, creating a cnfidential static claim value greater than 150 characters wuld generatee an errr. Knwn Issues in elease The fllwing knwn issues exist in the SSO API fr Federated Identity fr elease 3.2.. A knwn issue exists that generates a system fault when the IssueUserTken() peratin is invked with a null claimns value. A knwn issue exists that generates a null reference exceptin when invking the EST GetClaims and GetAllClaims peratins with empty r null tkens. Additinal esurces The fllwing nline dcumentatin prvides additinal infrmatin that can be referenced as supplemental material t these elease Ntes. Online Dcumentatin SSO API fr Federated Identity Prvides guidance t sftware develpers wh wish t leverage the SSO API fr Federated Identity t federate user identities acrss security dmains. Identity Federatin and single sign-n (SSO) are key cmpnents f the Cmmerce Mdule Certified Partner Prgram. ELEASE NOTE ES - 2
FO FEDEATED IDENTITY ELEASE NOTES Cmmerce Web Services SOAP Develper s Guide prvides an verview f the cmpnents and cncepts related t the develpment f client applicatins that cmmunicate with Cmmercee Web Services, as well as a step-by-step Services SOAP API. guide fr develping applicatins that implement the Cmmerce Web Cmmerce Web Services EST Develper s Guide prvides an verview f the cmpnents and cncepts related t the develpment f client applicatins that cmmunicate with Cmmercee Web Services, as well as a step-by-step Services EST API. guide fr develping applicatins that implement the Cmmerce Web Cmmerce Web Services Implementatin Guidelines is a supplemental resurce t the Cmmerce Web Services SOAP, EST, and TMS Develper s Guides that prvides guidelines, best practices, and wrkflww examples assciated with the implementatin f Cmmerce Web Services. Cmmerce Web Services Develper API eference prvides detailed infrmatin abut the Cmmerce Web Services API bjects and their crrespnding parameters and data elements, in additin t a CWS Fault eference. ELEASE NOTE ES - 3
FO FEDEATED IDENTITY ELEASE NOTES