Re: [Openstack] Keystone JSON format access control policy

2013-04-29 Thread Xiangjun Qian
Hey Tks man~ On Mon, Apr 29, 2013 at 3:00 PM, Dolph Mathews wrote: > The JSON approach is rather arbitrary; keystone has an API to manage & > publish policy blobs of any format (/v3/policies), and the policy engines > themselves are completely pluggable. I don't think there's anything > preventi

Re: [Openstack] Keystone JSON format access control policy

2013-04-29 Thread Dolph Mathews
The JSON approach is rather arbitrary; keystone has an API to manage & publish policy blobs of any format (/v3/policies), and the policy engines themselves are completely pluggable. I don't think there's anything preventing a deployment from implementing an XACML based policy solution (if there is

[Openstack] Keystone JSON format access control policy

2013-04-29 Thread Xiangjun Qian
Hi everyone, I'm currently looking at access control mechanisms of OpenStack and finding that the access control policy is specified using JSON format. I'm wondering why we do not adopt an XML based approach like XACML, is it because of the performance problem, or we just choose JSON as it's simp