[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [ggf-ogsa-sec-wg] inter-domain requirements
I am so relieved! I have been afraid that once we finished shoving all the hard problems from authentication to authorization we would be stuck with having to solve them. Now it appears there is a new distinction between authorization and policy management ... meaning that we can take the nastiest authorization problems and declare them policy management (to be solved later).
Sorry .... Von ... could you explain more about the "line" between policy management and authorization?
BC
>
>
> Olle,
>
> Thinking about the line between authorization assertions and policy
> management I've come to the conclusion that SAML (and other)
> authorization assertions are a form of policy management.
>