Re: Avoiding IBAC
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD5419591D6@G9W0755.americas.hpqcorp.net> |
Rob Meijer wrote: > > That is, at request time, the most essential difference between IBAC and > ZBAC should IMO be the type of attribute that 'identity' is considered to > be: An authority related or an auditing/logging related attribute. > A fair point. I'll use it when I'm explaining that you never know who did the access, only who is responsible for who did the access. It is a bit harder to explain, though, because how you do the auditing depends on the underlying mechanism. For example, with SAML, the delegation chain is in the assertion. With Horton, the audit information is distributed through the system. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp