Successfully reported this slideshow.

XACML in five minutes: excerpt from Catalyst 2013 panel "New school identity protocols fight for your love"

1

Share

Upcoming SlideShare
XACML - Fight For Your Love
XACML - Fight For Your Love
Loading in …3
×
1 of 20
1 of 20

XACML in five minutes: excerpt from Catalyst 2013 panel "New school identity protocols fight for your love"

1

Share

Download to read offline

In this panel hosted by Ian Glazer, my colleague Gerry Gebel introduces the audience to XACML and its latest developments including REST, JSON, and more developer-friendly initiatives.

In this panel hosted by Ian Glazer, my colleague Gerry Gebel introduces the audience to XACML and its latest developments including REST, JSON, and more developer-friendly initiatives.

More Related Content

Related Books

Free with a 14 day trial from Scribd

See all

Related Audiobooks

Free with a 14 day trial from Scribd

See all

XACML in five minutes: excerpt from Catalyst 2013 panel "New school identity protocols fight for your love"

  1. 1. Is XACML a Classic? Gerry Gebel @ggebel
  2. 2. XACML 3.0 is approved 10 vendors 5 end-user orgs Open source options Who’s the XACML Technical Committee?
  3. 3. RSA 2013 Interop When will Catalyst host the next interop?
  4. 4. StandardizedXACML is a Authorization language
  5. 5. CentralizedXACML enables Authorization
  6. 6. Attribute based XACML implements Access Control Check out the NIS Special Publication 800-162 on ABAC
  7. 7. Policy based XACML is a Access Control language
  8. 8. eXtensibleThe XACML language & architecture is
  9. 9. Fine grainedXACML allows for Authorization scenarios
  10. 10. Does this XML make me look fat? <xml/>
  11. 11. XACML JSON Profile 84% smaller 0 200 400 600 800 1000 1200 1400 Character Count XML JSON
  12. 12. REST Profile of XACML JSON XML
  13. 13. Protect In-depth XACML lets you SPF 5 to 50
  14. 14. Implement Segregation Of Duty Managers can approve a transaction if and only if they did not initiate it if and only if user.id != creator id Easily with XACML rules & attributes
  15. 15. Inherit Multiple Rules Managers can approve a transaction if and only if they did not initiate it And if it’s between 9am and 5pm And the amount is under the user’s lim XACML lets you And combine them into a single set
  16. 16. Device-awareXACML enables authorization for BYOD
  17. 17. kill the comma (the semi-colon too) Ian Glazer once claimed: “Kill IAM to save it”
  18. 18. a happy relationship XACML helps you build that lasts generations
  19. 19. XACML & OAuth OAuth 2.0  XACML 
  20. 20. XACML & SCIM XACML & SAML

Editor's Notes

  • SAML  so mature and prevalent that new alternatives are appearing. Simpler ways to deal with federationXACML  where’s the rebellion? It is modernizing from within: REST profile, JSON request/response, and even a lightweight JSON-based policy notation (work by the TELECOMMUNICATIONS SOFTWARE &amp; SYSTEMS GROUP – TSSG in Ireland)
  • Since we last spoke at Gartner in Dec. 2012, XACML 3.0 has finally become an official OASIS standardIt can be downloaded from the OASIS website (https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml)
  • Interop included:SOAP-basedREST-basedIP and EC profilesParticipants:BoeingOracleViewDSAxiomatics
  • EMCOracleAxiomatics
  • Protect APIs, services in a go with gateways, filters, firewalls…The same applies to databases and networks (IF-Map)
  • Direct relationshipsIndirect relationshipsGrant or deny a range of accessCare relationshipHierarchiesProxy-delegate4-eye principleSoD (negative relationship)
  • SAML can transport XACMLSAML can be used in XACML policiesSAML can carry attributes for XACMLSAML and XACML were designed from day 1 for separate and complementary functions
  • ×