Next in thread → Next in month →

RE: Thoughts on Registry Security

From
Patil, Sanjay <>
Date
2001-08-28T02:40:30+00:00
ID
89F2F878C590D411957600508BAF79AB0116B0CE@NETFXCH2
Thread
RE: Thoughts on Registry Security
Title: RE: ebXML Security subteam

 

These 
seem to be the minimum set of operations that 

we 
need to provide access control for,  under any plan.

Sounds 
good to me for V2.

thanks, 
Sanjay 
Patil 
---------------------------------------------------------------------------------------------------------- 

IONA 
Total 
Business Integration (TM) 
Phone: 408 
350 9619                                 
http://www.iona.com 

  
-----Original Message-----
From: Damodaran, Suresh 
  [mailto:]
Sent: Monday, August 27, 2001 
  4:35 PM
To: Damodaran, Suresh; 
  ''; 
  ''
Subject: RE: Thoughts on Registry 
  Security

  
Shall we restrict access control actions ( The 
  actions on the objects that need access control on)

  
to 
  the following for V2?

  
    - life cycle 
  operations

  
   - read operation

  
   - update operation

  
 

  
Cheers,

  
-Suresh

  
 

  
 

  
 

  
    
-----Original Message-----
From: Damodaran, Suresh 
    
Sent: Monday, August 27, 2001 11:28 AM
To: 
    ''; 
    ''
Subject: Thoughts on Registry 
    Security

    
Here are some rough thoughts - tell me what you 
    think.

    
Sanjay and Farrukh, I am much thankful for your 
    earlier comments

    
on 
    the topic.

    
 

    
From a broad perspective, making sure that the 
    registry has

    
contents that are trustworthy is important whether 
    the registry

    
is 
    an embedded application, or is used only by apps within the same 
    firewall,

    
or 
    is accessible to anyone with an internet connection. There are 
    various

    
ingredients that go into this. It appears to me 
    that the same use case,

    
such as accessing a registry may have different 
    security requirements

    
based on the actor. The distinction on which of the 
    above registry uses

    
to 
    target first, essentially boils down to which use case and which 
    actors

    
are relatively more important to us. For example, 
    is a Registry Guest

    
an 
    important actor from the point of view of Registry? Should a Registry 
    Guest

    
publish in the registry? We have not outlined the 
    security needs per use case or actors

    
Some broader near term issues:

    
 

    
1. 
    Authorized access to registry content is essential in any case. Aligning 
    with XACML is an 

    
issue.

    
2. 
    Using digital signature for source integrity is important if registry is 
    accessible

    
from anywhere. DS is also useful for message 
    digests for nonrepudiation. Data integrity

    
and confidentiality are more important in the 
    "public registry" case.

    
3. 
    Securing the dynamic data - only special actors can create these? If so what 
    is the requirement

    
on security?

    
 

    
Regards,

    
-Suresh
Next in thread → Next in month →