Uploaded image for project: 'Grouper'
  1. Grouper
  2. GRP-2468

New Content - ABAC, RBAC, and Grouper

    XMLWordPrintable

Details

    • Documentation
    • Resolution: Unresolved
    • Minor
    • None
    • None
    • grouperDeploymentGuide
    • None

    Description

      1. ABAC, RBAC, and Grouper - Chris Hyzer
      2. perhaps we should add a section that is more explicit about how 800-162 abac model is mapped to the GDG approach? and how that compares to RBAC?
      3. Make it more explicit, and explain how things relate to RBAC
      4. GDG takes spirit of the RBAC and ABAC standards
      5. Suggest that GDG is like RBAC or ABAC, and maybe summarize what is useful from it and how Grouper relates to it
      6. Grouper uses attributes (as explained in RBAC and ABAC), but Grouper does the access policy and Grouper has ad hoc attributes
      7. Use of permissions in Grouper is not exactly like in RBAC and ABAC
      8. Grouper uses hybrid model
      9. Matt: best to talk about natural language constructs versus talking about role or attribute
      10. Deployment model changes whether access control policy or whether its an  attribute
      11. Last mile to the application varies
      12. Something can be attribute to one application and a role to another
      13. Using the RBAC model doesn’t totally fit
      14. Good to mention that Grouper can support the models
      15. Focus on natural language
      16. Bill: good ideas  from RBAC are around unanticipated user, attributes on users change and can update automatically , Grouper does accomplish this
      17. SUMMARY:  GDG should tone down the emphasis on “you must read RBAC”
      18.   in the GDG intro, define ABAC and RBAC and say Grouper is related … then talk about natural language.

      Attachments

        Activity

          People

            bill.thompson.3@at.internet2.edu Bill Thompson
            bill.thompson.3@at.internet2.edu Bill Thompson
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: