90 likes | 226 Vues
This document details various authorized use cases for implementing Web Single Sign-On (SSO) solutions through Web Access Management (WAM) systems and SAML. It explores different scenarios including web applications and file access mediated by operating systems (OS), as well as remote network access to virtual private networks (VPNs). The document outlines the roles of various components including Policy Enforcement Points (PEPs), Policy Decision Points (PDPs), Policy Administration Points (PAPs), and associated utilities required for secure identity and access management.
E N D
Authorization Use Cases Identity and Authorization Services Working Group (IAS-WG) April, 2010
AuthZ Use Case - Web SSO via Web Access Management (WAM) System Target Resource Principal PEP WAM plug-in User/device HTML or web app Environment Time/Location PDP WAM Server PAP PIP WAM console LDAP
Use case details – Web SSO via Web Access Management (WAM) System
AuthZ Use Case - Web SSO via SAML Target Resource Principal PEP SAML-enabled Web app User/device HTML or web app Environment Time/Location PDP SAML server PAP PIP LDAP & SAML consoles LDAP
AuthZ Use Case – File access mediated by operating system (OS) Target Resource Principal PEP OS User/device File Environment Time/Location PDP OS PAP PIP OS utilities OS
Use case details – File access mediated by operating system (OS)
AuthZ Use Case – remote network access to virtual private network (VPN) Target Resource Principal PEP VPN User/device Network Environment Time/Location PDP RADIUS PAP PIP RADIUS utilities RADIUS DB
Use case details – remote network access to virtual private network (VPN)