Burden of Authorization
federator
wpadmin at identiainc.com
Thu Dec 18 16:52:25 EST 2014
Hi Tom, please see response below. thx. -- Nick
On 12/18/14 4:10 PM, Tom Scavo wrote:
> On Thu, Dec 18, 2014 at 3:41 PM, federator <wpadmin at identiainc.com> wrote:
>> I haven't seen any good implementation or even good use cases of using
>> centralized authorization.
> XACML defines the notion of a Policy Decision Point (PDP). There are
> PDP implementations and deployments but not in higher ed AFAIK.
PDP can be made centrally as well as locally on the SP side. It's a
matter of where you put it. Our consultants had tried to implement
centralized PDP for some government agencies on large scale project, and
didn't get any good results at all.
>
> A successor of XACML is called UMA:
> http://en.wikipedia.org/wiki/User-Managed_Access
I am not sure if this is a correct statement. According to the spec,
UMA is just a specific profile based on OAuth. Nevertheless, I don't
think UMA is relevant to the topic of centralized vs localized
authentication.
>
> Tom
More information about the users
mailing list