Sun and Oracle Community Voices How to Buy Log In United States [Change] English

»  Spotlight Articles
»  Projects
»  Publications
»  People
»  Awards
»  Events
»  Downloads
»  Internships
»  Contrarian Minds
»  About Sun Labs
XACML

XACML Project

Web Services Profile of XACML (WS-XACML)

The Web Services Profile of XACML (WS-XACML) is an active working draft within the OASIS eXtensible Access Control Markup Language (XACML) Technical Committee. It proposes XACML-based formats for Web Services policy Assertions for authorization and privacy policies. The formats allow the Assertions to be matched automatically.

XACML-based Web Services Policy Constraint Language (WS-PolicyConstraints) documents

WS-PolicyConstraints is a generic, domain-independent language for expressing constraints for a web services policy (constraints are also known as predicates or assertions). With this language, constraints for any type of policy can be written without requiring changes to the policy processor. WS-PolicyConstraints is designed to complement higher level policy frameworks (such as WS-Policy), as well as to facilitate policy intersection and direct verification of messages against policies. A module supporting policies written in the WS-PolicyConstraints language can co-exist with modules supporting domain-specific policy languages such as WS-SecurityPolicy or WS-ReliableMessaging policy

XACML-based Web Services Policy Language documents:

Much of WS-PolicyConstraints is based on the XACML-based Web Services Policy Language developed within the OASIS XACML TC: XACML profile for Web-services (WSPL).

OASIS eXtensible Access Control Markup Language (XACML) documents:

XACML is a standard language for expressing access control and privacy policies. It supports role based access control and is integrated with the OASIS Security Assertion Markup Language (SAML).

Other documents:

  • Policies in the Alphabet Soup Slides for keynote talk presented at IEEE Policy06 5 June 2006; review of policy languages and systems in standards; includes speaker's notes; pdf