← Prev in month ← Prev in thread
Next in thread → Next in month →

Explanation of the WS-XACML "Vocabulary" element

From
Anne Anderson
Date
2007-04-17T15:49:00+00:00
ID
Thread
Explanation of the WS-XACML "Vocabulary" element
Colleagues,

At the Face-to-Face in Austin, I was asked to write up an explanation of
WS-XACML's "Vocabulary" element on the mailing list.

IN THREE SENTENCES

==================

The Vocabulary elements in a WS-XACML policy Assertion contain URIs that
are associated with policy vocabulary specifications.  These
specifications collectively must define all the Attributes or XML
documents that are referenced by AttributeDesignators or
AttributeSelectors in the policy Assertion.  WS-XACML does not define
any particular format for the vocabulary specifications themselves.

IN MORE DETAIL :-)

==================

A. WS-XACML ASSERTIONS

======================

A policy "Assertion" in WS-XACML consists of a set of Requirements and a
set of Capabilities.

--------------------------

| Requirements
|
|
Vocabulary="URI1"
| <--defines "role", "level" and their values
|
|
| Capabilities
|
|
Vocabulary="URI2"
| <--defines "resource-id"
|
Vocabulary="URI3"
| <--defines a set of "resource-id" values
|
|

--------------------------

Figure 1: XACMLAuthzAssertion example

The Requirements are predicates, such as XACML
← Prev in month ← Prev in thread
Next in thread → Next in month →