Jump to: navigation, search

Difference between revisions of "Keystone-Essex-BP-AuthZ"

m
Line 1: Line 1:
__NOTOC__
 
 
'''Goals:'''
 
'''Goals:'''
  
Line 7: Line 6:
 
* Map users and groups to roles
 
* Map users and groups to roles
  
[[Image:Keystone-Essex-BP-AuthZ$ProposedKeystoneAuthZStructure.png]]
+
[[Image:ProposedKeystoneAuthZStructure.png]]

Revision as of 21:22, 16 February 2013

Goals:

  • Support a capability model (Ex: Delete Files) by allowing services identify capabilities by endpoint
  • Map capabilities to role, allowing a role to span multiple endpoints & services
  • Allow restrictions on capabilities to certain resources (ex: John Doe may have access to Delete Files but only on myserver.server.com).
  • Map users and groups to roles

ProposedKeystoneAuthZStructure.png