RE: [xacml-comment] XACML standard

From
Sagar Limaye <>
Date
2017-12-21T16:58:39+00:00
ID
Thread
RE: [xacml-comment] XACML standard
I understand the motivation, but almost all implementations of it have terrible documentation, some are not even free and the free ones don’t even work as described in the documentation. AuthzForce documentation is horrible, for example.
 I tried to install and use it, but my Eclipse IDE just doesn’t recognize its classes and functions. Ws02 server doesn’t give the correct responses to the requests against the policies I used, and it’s not free. The other implementations like Balana or SunXACML
 are either abandoned, or only support 2.0. All this makes me wonder why this standard exists. I don’t want to waste my time learning it anymore.

 

Sagar

From: rich levinson

Sent: Tuesday, December 19, 2017 7:09 PM

To: Sagar Limaye; 


Subject: Re: [xacml-comment] XACML standard

 

Hi Sagar,

I feel bad that you had difficulty w the std.

It is true that as a stand-alone document, it is pretty difficult

for a beginner to get a good understanding of the motivation

behind the standard, which is to standardize repreesentation

of security policy for authorization and/or authentication.

I would suggest using google to search for:

    xacml tutorial

Some of these tutorials may provide the necessary context

for being able to more effectively use the spec.

  Thanks,

  Rich Levinson

On 12/19/2017 1:14 PM, Sagar Limaye wrote:

Hi,

This is the worst standard I have ever seen. There is literally no documentation available to get beginners to use it. The implementations listed on the website are
 all half-assed, and some are non existent. I can't believe how much time I wasted this semester trying to research into XACML, it ruined the grade for one of my classes. I hope I never have to use this useless standard ever again.

Thanks for nothing,

Sagar