Next in thread → Next in month →

Re: [xacml] New Issue#61: WS-XACML: How are the contents ofXACMLAuthzAssertions represented in the base XACML Policies

From
Anne Anderson
Date
2006-12-20T21:30:00+00:00
ID
Thread
Re: [xacml] New Issue#61: WS-XACML: How are the contents ofXACMLAuthzAssertions represented in the base XACML Policies
Anthony Nadalin wrote On 12/20/06 10:12,:
> One thing that bothers me (well I have several),
>
> 1) is why is this called WS ? as I'm not seeing a tie to web services,
> just to WS-Policy

XACMLAssertions were originally designed as a way to include XACML
policies in WS-Policy instances, and thus tie XACML more directly to Web
services, but the XACMLAssertions are certainly useful for more than
WS-Policy.  WS-Authorization and WS-Privacy have been mentioned numerous
times, although I have not seen anything moving forward, and it seems to
me that the XACMLAuthzAssertion and the XACMLPrivacyAssertion should be
able to fill the roles possibly envisioned for those two specifications.

The other two parts of the WS-XACML specification - the authorization
token and passing Attributes in the SOAP header - are more explicitly
Web services oriented.

That said, the XACMLAssertions are useful both in WS-Policy and in other
contexts.  I have proposed dropping the non-Assertion sections from
WS-XACML, and if so, I would be open to changing the name to something
like "XACML Authorization and Privacy Policy Assertions" (XAPPA? :-)
> 2) missing the tie to WS-Security, as SAML is not the only assertions
> that are used, this effort should be able to tie into the claims used in
> WS-Security

Are you referring to ways an XACMLAssertion could refer to WS-Security
claims used in the SOAP Security Header?  I could define a new standard
vocabulary identifier for such claims, and could give an example of
placing constraints on them.  Do you want to supply an example of a
claim you would like to see used?
> 3) there are 2 sides the requestor and receiver, each should be able to
> represent policy, not seeing this clearly in this proposal

Section 6 of WD 8 shows a client XACMLPrivacyAssertion and a Service
XACMLPrivacyAssertion.  What more would you like to see?

The academic team I am working with has made use of XACMLAssertions in a
multi-stage privacy policy negotiation protocol, so once our paper is
finished, perhaps I could include that as an example that would show the
two sides even more clearly.

Thanks for the review and comments.

Regards,
Anne

>
> Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122
> Inactive hide details for Anne Anderson - Sun Microsystems
>
Next in thread → Next in month →