<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"><channel><title>Disruptive Library Technology Jester &#187; xacml</title> <atom:link href="http://dltj.org/tag/xacml/feed/" rel="self" type="application/rss+xml" /><link>http://dltj.org</link> <description>We&#039;re Disrupted, We&#039;re Librarians, and We&#039;re Not Going to Take It Anymore</description> <lastBuildDate>Mon, 06 Feb 2012 20:04:22 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <cloud domain='dltj.org' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' /> <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/us/</creativeCommons:license> <item><title>Access Management and Provisioning Technology</title><link>http://dltj.org/article/access-management-and-provisioning-technology/</link> <comments>http://dltj.org/article/access-management-and-provisioning-technology/#comments</comments> <pubDate>Tue, 18 Jul 2006 19:21:41 +0000</pubDate> <dc:creator>Peter Murray</dc:creator> <category><![CDATA[Fedora]]></category> <category><![CDATA[Library SOA]]></category> <category><![CDATA[Raw Technology]]></category> <category><![CDATA[acegi]]></category> <category><![CDATA[grouper]]></category> <category><![CDATA[internet2]]></category> <category><![CDATA[library service-oriented architecture]]></category> <category><![CDATA[nmi-edit]]></category> <category><![CDATA[provisioning]]></category> <category><![CDATA[Shibboleth]]></category> <category><![CDATA[signet]]></category> <category><![CDATA[spring framework]]></category> <category><![CDATA[xacml]]></category><guid isPermaLink="false">http://dltj.org/2006/07/access-management-and-provisioning-technology/</guid> <description><![CDATA[Building on the shoulders of others &#8212; isn&#8217;t that how that quote goes? There has been a stack of printouts on my desk for a while now for various access management and service provisioning technologies. Rather than keep the paper, &#8230; <a href="http://dltj.org/article/access-management-and-provisioning-technology/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description> <content:encoded><![CDATA[<abbr class="unapi-id ignore noPrint" title="http://dltj.org/2006/07/access-management-and-provisioning-technology/"></abbr><p>Building on the shoulders of others &#8212; isn&#8217;t that how that quote goes?  There has been a stack of printouts on my desk for a while now for various access management and service provisioning technologies.  Rather than keep the paper, I&#8217;m putting the list here so I know how to get back to them if/when I need to.  (Of course, along the way if you&#8217;d like to comment on them or suggest others to look at, please feel free to do so in the comments.)  Note, too, that by listing them here I&#8217;m not proposing, or even sure if, all of these pieces come together to a coherent structure.</p><p><h2>Grouper &#8212; Internet2 Middleware</h2><br />&#8220;<a href="http://middleware.internet2.edu/dir/groups/grouper/" title="Grouper --- Internet2 Middleware">Grouper</a> is an open source toolkit for managing groups. It is designed to function as the core element of a common infrastructure for managing group information across integrated applications and repositories. Grouper combines multiple sources of group information, both automated and manual, in managing memberships and other group information in a Group Registry, a central information asset complementary to a site&#8217;s Person Registry.  Grouper manages two primary types of objects: groups and namespaces. Groups are created and named within a namespace. Group management authority can be limited &#8221;</p><p>Now at version 0.9, Grouper is part of a suite of tools from the <a href="http://www.nsf-middleware.org/" title="http://www.nsf-middleware.org/">NSF Middleware Initiative (NMI)</a> that supports &#8220;development, testing, and dissemination of architectures, software, and practices in the areas of identity and access management.&#8221;</p><p><h2>Signet &#8211; Internet2 Middleware</h2><br />&#8220;Core middleware services such as identity management, directory, and authentication provide a foundation for secure, manageable applications throughout an institution. Even with this foundation, as systems and applications proliferate it becomes more and more difficult to manage user access consistently and cost-effectively. [The <a href="http://middleware.internet2.edu/signet/" title="Signet - Internet2 Middleware">Signet] privilege management service</a> is a relatively new component of campus middleware that addresses this problem by providing centralized management of user privileges across a range of applications.  The benefits of this service include:  a standard user interface for privilege administrators; consistent, simplified policy definition, via roles and integration with core campus organizational data; improved visibility, understandability, and auditability of privilege information; and standard interfaces to other infrastructure services and to application systems to support integration.&#8221;</p><p>Now at version 1.01, released 29-Mar-2006.  Could this kind of provisioning service be used to generate XACML files to drive FEDORA?</p><p><h2>OASIS eXtensible Access Control Markup Language (XACML)</h2><br />&#8220;<a href="http://www.oasis-open.org/committees/xacml/" title="http://www.oasis-open.org/committees/xacml/">XACML</a> is expected to address fine grained control of authorized activities, the effect of characteristics of the access requestor, the protocol over which the request is made, authorization based on classes of activities, and content introspection (i.e. authorization based on both the requestor and potentially attribute values within the target where the values of the attributes may not be known to the policy writer). XACML is also expected to suggest a policy authorization model to guide implementers of the authorization mechanism.&#8221;</p><p><a href="http://sunxacml.sourceforge.net/" title="Sun&#039;s XACML Implementation">Sun&#8217;s XACML Implementation</a> (available at Sourceforge) is the access management engine embedded into the FEDORA repository.</p><p><h2>Acegi Security System for Spring</h2><br />&#8220;<a href="http://www.acegisecurity.org/" title="http://www.acegisecurity.org/" class="broken_link" rel="nofollow">Acegi Security</a> is a powerful, flexible security solution for enterprise software, with a particular emphasis on applications that use <a href="http://www.springframework.org/" title="Springframework.org">Spring</a>. Using Acegi Security provides your applications with comprehensive authentication, authorization, instance-based access control, channel security and human user detection capabilities.&#8221;</p><p>Release 1.0.0 came out in May 2006 after nearly two years of development.</p>]]></content:encoded> <wfw:commentRss>http://dltj.org/article/access-management-and-provisioning-technology/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
<!-- Served from: dltj.org @ 2012-02-11 09:16:57 by W3 Total Cache -->
