[jboss-dev-forums] [PicketBox Development] - Re: Get something started with XACML - Requirements Discussion

Dan Gradl do-not-reply at jboss.com
Tue Nov 22 11:50:39 EST 2011


Dan Gradl [http://community.jboss.org/people/dgradl] created the discussion

"Re: Get something started with XACML - Requirements Discussion"

To view the discussion, visit: http://community.jboss.org/message/637775#637775

--------------------------------------------------------------
So upstream, PicketBox XACML can be used to protect my web resources or my EJBs, right?   But still the end user is the one who hooks it in and writes policies and configures it and all of that right?     Unless the policies are prewritten and provided by those upstream projects, there is at least one pain point to using this project I would say.    If all this was used for was to protect various container resources, wouldn't you still need to address some of the concerns I am referring to?

i.e.
Performance is still important
Policy writing is still painful (wouldn't a PAP be useful?)
Might someone still want to be able to report and audit on the access granted to those resources?
Isn't there still a set of resources to manage? (EJBs, Servlets, etc)


I don't suppose XACML is a mandatory part of the JBoss AS, but it is there in case you need to provide fine grained access control to resources.  Still these things would make it easier to leverage for that purpose.   

Yea I can also see these capabilities also enabling a standalone XACML platform that could be used outside of JBoss, and a few things I mentioned may only make sense in that arena.

Before we spawn a project though, I guess we should see if anyone is interested in these things.   

--------------------------------------------------------------

Reply to this message by going to Community
[http://community.jboss.org/message/637775#637775]

Start a new discussion in PicketBox Development at Community
[http://community.jboss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2088]

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/jboss-dev-forums/attachments/20111122/df660942/attachment.html 


More information about the jboss-dev-forums mailing list