Download presentation
Presentation is loading. Please wait.
Published byNorma Stone Modified over 9 years ago
1
asap://www.XACML. jury-rigged
2
ClientPEP PDP
3
PolicySet Rule 1 Rule 2 etc Rule 1 Rule 2 etc Rule 1 Rule 2 etc Policy 1 Policy 2 Policy 3
4
Target Condition Rule
5
Subject Resource Action Target
6
<Attribute AttributeId=“” DataType =“” … + + Subject can have one or more ‘Attribute’
7
<Attribute AttributeId=“” DataType =“” … 1 1 Resource can have only 1 ‘Attribute’
8
<Attribute AttributeId=“” DataType =“” … + + Action can have one or more ‘Attributes’
9
Confused about Target? Either inside Policy/PolicySet or Rule When inside Policy/PolicySet, Target provides more of meta-data. When inside a Rule, Target provides info required to process the rule.
10
There are 3 or more XML files in the works each time a request goes to PEP Client (Requestor) PEPPDP Policy DB 1.Authorization Request in day to day format 2. Authorization Request translated into XML format (1 st XML file) 4. Permit/Deny XML file (2 nd XML file) 3. Compare policy from step 2 with the ones in DB. (the third or more xml files)
11
An example of these 3 XML files Request XML File Taken from http://sunxacml.sourceforge.net/guide.html#xacml-target Request XML File
12
An example of these 3 XML files Policy XML File This Target provides meta-data
13
An example of these 3 XML files Policy XML File This Target provides rule processing info
14
An example of these 3 XML files Response/Decision XML File
15
Resources and References Sun’s XACML Implementation http://sunxacml.sourceforge.net/
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.