|
From: Rod J. <rod...@in...> - 2004-01-12 08:51:03
|
Yes, security is an isue that has come up several times in the spring-user list. Someone proposed a pretty comprehensive solution. Security will be considered as a new feature in Spring 1.1. Thanks for the suggestions. Rod ----- Original Message ----- From: "Double Delight" <dou...@ya...> To: <spr...@li...> Sent: Sunday, January 11, 2004 10:39 PM Subject: [Springframework-developer] Security SPI: Access Control > The Spring Security SPI would look like: > -- Authentication: Pluggable providers for SAML, > WS-Security, ProjectLiberty, etc. > -- Access Control: Pluggable providers for XACML, > RBAC (Roles Based Access Control) > > > Since Authentication has been done many times, lets > focus on providing a standards based Access Control > solution. After much looking around, XACML seems to > be the standard and they have a RBAC profile also. > > XACML Links: > http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml > > > OpenSource XACML engine: > http://sunxacml.sourceforge.net/ > > Research proposal for including XACML in J2SE: > http://research.sun.com/projects/xacml/J2SEPolicyProvider.html > > > Most importantly, RBAC implemented with XACML: > http://www.oasis-open.org/committees/download.php/2405/wd-xacml-rbac-profile -01.doc > > > Cheers, > -- DD > > > __________________________________ > Do you Yahoo!? > Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes > http://hotjobs.sweepstakes.yahoo.com/signingbonus > > > ------------------------------------------------------- > This SF.net email is sponsored by: Perforce Software. > Perforce is the Fast Software Configuration Management System offering > advanced branching capabilities and atomic changes on 50+ platforms. > Free Eval! http://www.perforce.com/perforce/loadprog.html > _______________________________________________ > Springframework-developer mailing list > Spr...@li... > https://lists.sourceforge.net/lists/listinfo/springframework-developer > |