Yes, security is an isue that has come up several times in the spring-user
list. Someone proposed a pretty comprehensive solution.
Security will be considered as a new feature in Spring 1.1.
Thanks for the suggestions.
Rod
----- Original Message -----
From: "Double Delight" <dou...@ya...>
To: <spr...@li...>
Sent: Sunday, January 11, 2004 10:39 PM
Subject: [Springframework-developer] Security SPI: Access Control
> The Spring Security SPI would look like:
> -- Authentication: Pluggable providers for SAML,
> WS-Security, ProjectLiberty, etc.
> -- Access Control: Pluggable providers for XACML,
> RBAC (Roles Based Access Control)
>
>
> Since Authentication has been done many times, lets
> focus on providing a standards based Access Control
> solution. After much looking around, XACML seems to
> be the standard and they have a RBAC profile also.
>
> XACML Links:
> http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml
>
>
> OpenSource XACML engine:
> http://sunxacml.sourceforge.net/
>
> Research proposal for including XACML in J2SE:
> http://research.sun.com/projects/xacml/J2SEPolicyProvider.html
>
>
> Most importantly, RBAC implemented with XACML:
>
http://www.oasis-open.org/committees/download.php/2405/wd-xacml-rbac-profile
-01.doc
>
>
> Cheers,
> -- DD
>
>
> __________________________________
> Do you Yahoo!?
> Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes
> http://hotjobs.sweepstakes.yahoo.com/signingbonus
>
>
> -------------------------------------------------------
> This SF.net email is sponsored by: Perforce Software.
> Perforce is the Fast Software Configuration Management System offering
> advanced branching capabilities and atomic changes on 50+ platforms.
> Free Eval! http://www.perforce.com/perforce/loadprog.html
> _______________________________________________
> Springframework-developer mailing list
> Spr...@li...
> https://lists.sourceforge.net/lists/listinfo/springframework-developer
>
|