[Standards] Veto on "Privileged Entity"
dave at cridland.net
Tue Dec 16 22:05:57 UTC 2014
On 16 Dec 2014 21:21, "Kurt Zeilenga" <kurt.zeilenga at isode.com> wrote:
> And can I draw the conclusion you think XACML is the “standard industry
model and terms” specification that you want this work “recast” in?
No, but it uses the same ABAC model as of NIST and others. None of these
specifications are particularly approachable, but they're largely in
agreement as regards terms and model.
For what it's worth, I'm not sure that the 258 work would ever quite sit in
the same model, at least not without a SPIF-aware PDP.
Using the same model would, of course, mean that one could hand
authorization decisions to a standard XACML PDP, but wouldn't have to, and
I doubt many would want to.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Standards