XACML in five minutes: excerpt from Catalyst 2013 panel "New school identity protocols fight for your love"
Aug. 1, 2013•0 likes
1 likes
Be the first to like this
Show More
•3,136 views
views
Total views
0
On Slideshare
0
From embeds
0
Number of embeds
0
Download to read offline
Report
Technology
Business
In this panel hosted by Ian Glazer, my colleague Gerry Gebel introduces the audience to XACML and its latest developments including REST, JSON, and more developer-friendly initiatives.
Implement
Segregation
Of Duty
Managers can approve a transaction
if and only if they did not initiate it
if and only if user.id != creator id
Easily with XACML rules & attributes
Inherit
Multiple
Rules
Managers can approve a transaction
if and only if they did not initiate it
And if it’s between 9am and 5pm
And the amount is under the user’s lim
XACML lets you And combine them into a single set
SAML so mature and prevalent that new alternatives are appearing. Simpler ways to deal with federationXACML where’s the rebellion? It is modernizing from within: REST profile, JSON request/response, and even a lightweight JSON-based policy notation (work by the TELECOMMUNICATIONS SOFTWARE & SYSTEMS GROUP – TSSG in Ireland)
Since we last spoke at Gartner in Dec. 2012, XACML 3.0 has finally become an official OASIS standardIt can be downloaded from the OASIS website (https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml)
Interop included:SOAP-basedREST-basedIP and EC profilesParticipants:BoeingOracleViewDSAxiomatics
EMCOracleAxiomatics
Protect APIs, services in a go with gateways, filters, firewalls…The same applies to databases and networks (IF-Map)
Direct relationshipsIndirect relationshipsGrant or deny a range of accessCare relationshipHierarchiesProxy-delegate4-eye principleSoD (negative relationship)
SAML can transport XACMLSAML can be used in XACML policiesSAML can carry attributes for XACMLSAML and XACML were designed from day 1 for separate and complementary functions