90 likes | 212 Vues
This document details various authorization use cases involving Web Single Sign-On (SSO) through Web Access Management (WAM) systems. It covers scenarios such as web SSO via WAM and SAML-enabled web applications, file access mediated by operating systems, and remote network access to virtual private networks (VPNs). Each use case outlines the target resource, principal elements, and the roles of Policy Enforcement Points (PEPs), Policy Decision Points (PDPs), and other components in the authorization framework, enriching the understanding of modern identity and access management.
E N D
Authorization Use Cases Identity and Authorization Services Working Group (IAS-WG) April, 2010
AuthZ Use Case - Web SSO via Web Access Management (WAM) System Target Resource Principal PEP WAM plug-in User/device HTML or web app Environment Time/Location PDP WAM Server PAP PIP WAM console LDAP
Use case details – Web SSO via Web Access Management (WAM) System
AuthZ Use Case - Web SSO via SAML Target Resource Principal PEP SAML-enabled Web app User/device HTML or web app Environment Time/Location PDP SAML server PAP PIP LDAP & SAML consoles LDAP
AuthZ Use Case – File access mediated by operating system (OS) Target Resource Principal PEP OS User/device File Environment Time/Location PDP OS PAP PIP OS utilities OS
Use case details – File access mediated by operating system (OS)
AuthZ Use Case – remote network access to virtual private network (VPN) Target Resource Principal PEP VPN User/device Network Environment Time/Location PDP RADIUS PAP PIP RADIUS utilities RADIUS DB
Use case details – remote network access to virtual private network (VPN)