OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cmis-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cmis-comment] Security and authentication issues


Fernando,

Thank you taking the time to investigate the current specification. I'd like to address your points:

1. Authentication is covered by the bindings themselves and we did not feel a need to reinvent the wheel there. For ReSTfule AtomPub binding, which is based on HTTP, HTTP Basic, Digest, NTLM, or some other mechanism can be implemented. For WS binding, WS-Security or HTTP authentication is also valid. For both of these bindings, many tools are available to send and receive credentials. If this is not sufficient, could you explain your use case?

2. Security - We currently expose the ability to see what actions the current user can perform. We also expose an abstract policy based mechanism that can affect the security policies in the repository. We are also working on a simple form of ACL as well.

Does the above address your concerns? If not, I'd like to continue the discussion on what use cases you are trying to solve and how CMIS can be used for them.

Thanks,
-Al

Al Brown
Emerging Standards and Industry Frameworks
CMIS: https://w3.tap.ibm.com/w3ki07/display/ECMCMIS/Home
Industry Frameworks: https://w3.tap.ibm.com/w3ki07/display/ECMIF/Home

Office 714 327 3453
Mobile 714 263 6441
Email albertcbrown@us.ibm.com
CONFIDENTIAL NOTICE: The contents of this message, including any attachments, are confidential and are intended solely for the use of the person or entity to whom the message was addressed. If you are not the intended recipient of this message, please be advised that any dissemination, distribution, or use of the contents of this message is strictly prohibited. If you received this message in error, please notify the sender. Please also permanently delete all copies of the original message and any attached documentation.

Inactive hide details for Fernando Díaz Gestal ---03/04/2009 04:49:57 AM---Hello guys,Fernando Díaz Gestal ---03/04/2009 04:49:57 AM---Hello guys,


From:

Fernando Díaz Gestal <fernando.diaz@mykubbe.com>

To:

cmis-comment <cmis-comment@lists.oasis-open.org>

Date:

03/04/2009 04:49 AM

Subject:

[cmis-comment] Security and authentication issues





Hello guys,

First of all, I have to say that CMIS is a very good start point for the standarization of CMS-based applications.

But in my opinion there are two important points that CMIS doesn't cover:
* Authentication: There aren't any primitives in order to acomplish the user authentication against the repository.
* Security: There aren't any primitives to manage the securiry and the permissions of the different parts of the repository.

For these reasons is not possible to create an CMS-based application which can use whatever CMS through CMIS. We need to develop authentication and security bussiness cases for each CMS that we want to be compatible.

It's a pitty that the standard don't cover these points.

What do you think?

Regards

Fernando Díaz Gestal
Kubbe Solutions
NETEX KNOWLEDGE FACTORY
fernando.diaz@@mykubbe.com

http://www.mykubbe.com
http://www.netex.es



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]