Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migration of unmigrated content due to installation of a new plugin

...

Section
borderfalse
Column
width60%

The MACE-paccman working group is dormant for now. Please contact Emily Eisbruch at i2mi-info@internet2.edu, with questions or comments.

The MACE-paccman Working Group provides a venue for discussion and development of access management material in the context of MACE and the Internet2 Middleware Initiative. It is was co-chaired by Tom Dopirak, Carnegie Mellon University, and Keith Hazelton, University of Wisconsin - Madison. Working Group Flywheel is Steve Olshansky <steveo AT internet2.edu>.

For editing access to this wiki space, see the instructions at http://middleware.internet2.edu/docs/internet2-spaces-instructions-200703.html

Also see the MACE-paccman website, which includes:

  • minutes of conference calls
  • instructions for subscribing to the mailing list
  • finalized documents and other deliverables, as they become available
  • links to related resources of interest
Column
Info

 The MACE-paccman Working Group meets every other Thursday at 1 PM ET

Next Meeting: August 16, 2012

Call and agenda information is provided via the MACE-paccman mailing list

What are we currently working on ?

Projects

  1. Federated Authorization Problems and Models
  2. The Recipe for Privilege and Access Management
  3. Looking at feedback from the August 8 AIM online Looking at selected use cases with a policy service perspective approach, and modeling using XACML terminology (PAP, PIP, PEP, PDP)
  4. Simple Cloud Identity Management (SCIM) protocol as candidate for (de)provisioning
    1. Namespaces for privileges and expressing them through URI and URNs
    2. When to use groups , roles, privileges
    3. Role Hierarchies
    4. Working examples  of Access Management
  5. Using the paccman glossary in other MACE Working Groups
  6. Experiments with the Axiomatics Policy Engine
  7. How can privileges be provisioned into an existing application?
  8. A mace-wide access management glossary

...

Documents and Presentations

  • CIFER Project
  • Classification of Authorization Use Cases addressed by XACML from Gartner, Inc. Author: Bob Blakely
  • Policy Engine / PDP initiative
    At Advanced CAMP this past summer 2010, several middleware initiatives were launched. One of them, led by Leif Johansson and Keith Hazelton, is on policy engine evaluation using the featured Paccman MACE-paccman use cases.
  • Grouper
    Anyone needing to manage group access to resources can use Grouper - from accountants to zoologists. A researcher might create a group and enable members to participate on an email list or view a web site. Students might use Grouper to set up and manage groups for similar applications as they work together on shared projects and class work. Your IT staff can delegate group management and enable those leading collaborations to set up and manage their own groups.
  • Permis
    PERMIS provides you with the software that makes access control decisions, and also gives you the tools for managing your policies, your role assignments, and delegations between users
  • Kuali Identity Management (KIM)
    KIM provides central identity and access management services. It also provides management features for Identity, Groups, Roles, Permissions, and their relationships with each other.
  • perMIT Project (MIT)
    The perMIT project's purpose is to translate MIT's RolesDB, in production use for over 10 years, to an open source community project and finally deliver to the world a usable Permission Management System.
  • spocp SPOCP (pronounced as SPOCP, for Simple Policy Control Protocol) is a very efficient rule-based authorization engine
  • drools Drools is at its core a combination rules engine and process management package. Grouper's rule service is based on Drools. The rabbit hole entrance sign says: Welcome
  • We believe there is a strong affinity between access management and provisioning. Some of the effort associated with the Open Source IDM for Higher Ed (OSIDM4HE) CIFER project may be of interest, especially the work underway in the OSIDM4HE the  Provisioning Subgroup.
  • Simple Cloud Identity Management (SCIM)