|
From: Double D. <dou...@ya...> - 2004-01-11 22:39:08
|
The Spring Security SPI would look like: -- Authentication: Pluggable providers for SAML, WS-Security, ProjectLiberty, etc. -- Access Control: Pluggable providers for XACML, RBAC (Roles Based Access Control) Since Authentication has been done many times, lets focus on providing a standards based Access Control solution. After much looking around, XACML seems to be the standard and they have a RBAC profile also. XACML Links: http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml OpenSource XACML engine: http://sunxacml.sourceforge.net/ Research proposal for including XACML in J2SE: http://research.sun.com/projects/xacml/J2SEPolicyProvider.html Most importantly, RBAC implemented with XACML: http://www.oasis-open.org/committees/download.php/2405/wd-xacml-rbac-profile-01.doc Cheers, -- DD __________________________________ Do you Yahoo!? Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes http://hotjobs.sweepstakes.yahoo.com/signingbonus |