GT 3.9.4 Component Fact Sheet: WS A&A Authorization Framework

Brief overview

The WS Authentication and Authorization component allows for a variety of authorization schemes, including the use of the grid-mapfile, an access control list defined by a service, a custom authorization handler and the use of an authorization service via the SAML protocol.

Summary of features

Features new in release 3.9.4

  • SAML callout enables outsourcing of authorization decisions to an authorization service (e.g. PERMIS)

Other Supported Features

  • Authorization based on grid-mapfile and other access control lists
  • Ability to implement custom authorization modules

Deprecated Features

  • None

Backward compatibility summary

Protocol changes in the Authorization Framework since GT version 3.2

  • Addition of the SAML authorization callout

API changes since GT version 3.2

  • None

Exception changes since GT version 3.2

  • None

Schema changes since GT version 3.2

  • None

Technology dependencies

The WS Authentication and Authorization component depends on the following GT components:

  • WS Authentication and Authorization Message-Level Security

The WS Authentication and Authorization components depends on the following 3rd party software:

  • OpenSAML

Tested platforms

Tested Platforms for WS Authorization Framework:

  • Linux (Red Hat 7.3)
  • Windows 2000
  • Solaris 9