The SAML XML.org web site is not longer accepting new posts. Information on this page is preserved for legacy purposes only. For current information on SAML, please see the OASIS Security Services Technical Committee Wiki.
Diff for XACML OASIS Standard
Wed, 2007-12-12 22:19 by carolgeyer | Wed, 2007-12-12 22:24 by carolgeyer | ||
---|---|---|---|
Changes to Body | |||
Line 9 | Line 9 | ||
request/response language expresses queries about whether a particular
| request/response language expresses queries about whether a particular
| ||
access should be allowed (requests) and describes answers to those
| access should be allowed (requests) and describes answers to those
| ||
- | queries (responses).
| + | queries (responses).
|
</p>
| </p>
| ||
+ | <h3>XACML and SAMLÂ </h3>
| ||
<p>
| <p>
| ||
The newest versions of XACML and SAML have been
| The newest versions of XACML and SAML have been
|
XACML OASIS Standard
The eXtensible Access Control Markup Language (XACML) OASIS Standard is an XML-based language for access control.
XACML describes both an access control policy language and a request/response language. The policy language is used to express access control policies ('who can do what when'). The request/response language expresses queries about whether a particular access should be allowed (requests) and describes answers to those queries (responses).
XACML and SAMLÂ
The newest versions of XACML and SAML have been designed to complement each other; for example, an XACML policy can specify what a provider should do when it receives a SAML assertion, and XACML-based attributes can be expressed in SAML.