It will probably be easier to follow my upcoming posts about how I have enabled my requirements of the STS in WCF if you have a good understanding of the security architecture of WCF.
This is a good starting point if you don't have that understanding.