Burden of Authorization

federator wpadmin at identiainc.com
Thu Dec 18 16:52:25 EST 2014


Hi Tom, please see response below.  thx.  -- Nick
On 12/18/14 4:10 PM, Tom Scavo wrote:
> On Thu, Dec 18, 2014 at 3:41 PM, federator <wpadmin at identiainc.com> wrote:
>> I haven't seen any good implementation or even good use cases of using
>> centralized authorization.
> XACML defines the notion of a Policy Decision Point (PDP). There are
> PDP implementations and deployments but not in higher ed AFAIK.
PDP can be made centrally as well as locally on the SP side.   It's a 
matter of where you put it.  Our consultants had tried to implement 
centralized PDP for some government agencies on large scale project, and 
didn't get any good results at all.
>
> A successor of XACML is called UMA:
> http://en.wikipedia.org/wiki/User-Managed_Access
I am not sure if this is a correct statement.  According to the spec, 
UMA is just a specific profile based on OAuth.  Nevertheless, I don't 
think UMA is relevant to the topic of centralized vs localized 
authentication.
>
> Tom



More information about the users mailing list