You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

  • privileges, a generic model
    • group, role and role hierarchies, draft proposal for MACE-wide model and definition
      • Are the definitions in the glossary good enough or are their others that are more widely accepted?
        • mace documents ( grouper)  vs other standards groups
    • case studies
  • attribute delivery recipe:
    • SAML between IdP & SP
    • SPML, XMPP ( grouper) for push provisioning
    • LDAP , privilege registry or webservice   for pull provisioning
      • is there existing mace-dir work to build on?
  • generalizing to federated scenarios and VOs
    • What is the namespace and object characteristics for privileges
      • what are the special problems in namespace choice?
      • Fifer using URIs
  • authorization and access control
    • case studies in production
  • rule-based access control
    • XACML , DROOLS, others
  • policy, a generic model
    • P*P architectures: proposed models,
      • Application policy, enterprise policy, VO policy
    • case studies - bamboo
  • No labels