[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Subject: [xacml] updated future work list
I've incorporated the additional items suggested by Carlisle and Michiharu]. Anne Title: Possible Future XACML TC Work Version: 1.3, 03/02/13 (yy/mm/dd) 1. XACML 1.0+: RFE's based on actual usage a) Fully specify hierarchical resources b) Define new combining algorithms for deterministic Obligations. c) ebXML: Allow references to Rules (as we now allow for policies and policy sets) d) Incorporate fixes for errata e) Condition reference: From the policy, a specific condition expression is referred to by using condition ID that is defined in the condition definition block. [Michiharu] f) Properties for new combining algorithms [Michiharu] g) Obligations in rule element [Michiharu] 2. Profiles and bindings a) SAML: revised AuthorizationDecisionStatement, AuthorizationDecisionQuery, Response to support XACML Request and Response Context [Anne and Hal working on this] b) XMLDSig: how to sign XACML policies, requests, responses [Anne working on this] c) LDAP: 1) how to store and retrieve policies using LDAP 2) how to store and retrieve attributes using LDAP [already defined? Simon?] d) ebXML: 1) how to store and retrieve policies using ebXML 2) how to store and retrieve attributes using ebXML e) Transport protocols (in addition to SAML wrapper) f) Define a set of domain-specific identifiers (action, combining algorithm etc.) that are used in well-known domains e.g. UNIX ACL, Windows, database ... [Michiharu] 3. Additional Conformance Tests 4. XACML Extensions a) WS-Policy [Tim] b) Information about how/where to obtain policies and attributes; how to authenticate them (e.g. trust anchors) 5. XACML Primer [Hal and Konstantin working on this] 6. XACML Implementer's Guide 7. Exploration of whether and how XACML can be used to express privacy policies [Carlisle, Bill]
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Powered by eList eXpress LLC