It allows a network access server (NAS) to perform authentication, authorization, and accounting for users.
它允许网络访问服务器(NAS)执行对用户的验证、授权和记帐。
If only the identity of the middle tier service is propagated to the downstream service, the downstream service does not have proper control over audit and authorization of access to the service.
如果只有中间层服务的标识传播到下游服务,则下游服务不能对服务访问审核和授权进行正确的控制。
This activity is usually performed for network access authorization and authentication, content filtering, or to better utilize network bandwidth through caching.
通常为了进行网络访问授权和身份验证、内容筛选或通过缓存更好地利用网络带宽而进行此活动。
This includes identification and authentication, authorization, access control, data masking, auditing, and encryption.
这包括识别、认证、授权、访问控制、数据屏蔽、审计和加密。
Together, the default role and default policy make up the default authorization: the implicit rule of access on the cube for users with no explicit rule of access.
默认角色和默认策略共同构成默认授权:多维数据集上针对没有显式访问规则的用户的隐式访问规则。
It provides the consistent authentication and authorization services necessary for universal access.
它为通用访问提供了所需的一致的身份验证和授权服务。
A typical access control and authorization scenario includes three main entities — a subject, a resource, and an action — and their attributes.
典型的访问控制和授权场景包括三个主要实体:主体、资源和动作以及它们的属性。
They both share a lot of concepts and a domain — the domain of authentication, authorization, and access control.
它们有很多相同的概念,要处理的问题域也在很大程度上重叠:验证、授权和访问控制。
XACML builds on SAML by providing the actual semantics used to define access control policy and authorization request and response messages.
XACML构建于SAML之上,提供了用于定义访问控制和授权请求及响应消息的实际语义。
It is essential to consider the possible access paths to every layer of a system, and also to consider how authorization integrates with other security aspects, such as network level protection.
务必考虑系统的每个层次的可能访问路径,同时还要考虑授权如何与其他安全功能(如网络级别的保护)集成。
If you solved these problems in traditional way, service usage may become cumbersome due to multiple Authentication and Authorization systems needed to give partners access.
如果按照传统的方式解决这些问题,那么服务的使用将变得非常复杂,因为需要使用多个身份验证和授权系统来实现合作伙伴访问。
Secure integration and access to business applications and information is typically achieved through authentication, authorization, and accountability.
安全集成以及对业务应用程序和信息的访问通常是通过身份验证、授权和责任实现的。
Service usage is cumbersome due to multiple Authentication and Authorization systems needed to give partners access.
由于合作伙伴需要访问多个身份验证和授权系统,因此服务的使用变得非常的繁琐。
The PEP fulfills the obligations and, based on the authorization decision sent by PDP, either permits or denies access.
PEP履行义务,并根据PD P发送的授权决策允许或拒绝访问。
In addition, the access ID of the user or the user's group from an the job manager needs to be imported into the local authorization table and given a role.
此外,需要将来自作业管理器的用户或用户组的访问ID导入到本地授权表并赋予其角色。
All users who do not belong to a role with explicit authorization on the dimension are members of the default role, and they are able to access the dimension according to the default policy.
只要用户不属于对维度具有显式授权的角色,它就属于默认角色的成员,可以根据默认策略访问该维度。
And once you have authorization, you'll want to store that connection for long-term use so that you don't have to ask the user for permission to access their resources again.
一旦通过了授权,就会去想如何把这种长连接持久化,以至于不用每次在访问资源时都要再授权。
After completing the steps described above, you are ready to include all authentication and authorization activities through the configured Access Manager client in any AAA action.
完成上述步骤以后,您就准备好通过已配置的AccessManager客户端在任何AAA操作中包括所有身份验证和授权活动了。
Realm Write operations: Currently all Realm implementations support 'read' operations for acquiring authentication and authorization data to perform logins and access control.
Realm写操作:目前所有Realm实现都支持“读”操作来获取验证和授权数据以执行登录和访问控制。
The authorization policies defined to the Object Authority Manager (OAM) control access based on user IDs and group membership.
ObjectAuthorityManager (oam)中定义的授权策略可以基于用户ID和组成员身份进行访问控制。
Now, let's go back and take a look at how we would solve our printer authorization problem using Tivoli Access Manager.
现在让我们回头看看如何使用TivoliAccessManager解决我们的打印机授权问题。
Application resources like EJB methods and Web pages can be declared to require authorization for access by means of security constraints in deployment descriptors.
通过部署描述符中的安全约束,可以将应用程序资源(如ejb方法和web页)声明为需要授权才能进行访问。
If the application contains a mixture of secure (those with authorization constraints) and insecure servlets, the insecure servlets cannot access the session object.
如果应用程序包含安全的(具有授权约束的)和不安全的Servlet的混合体,则不安全的Servlet将无法访问会话对象。
Ben also talked about advanced web security requirements like method level authorization, JSR-250 for defining method security metadata, Spring security method metadata, and domain access control.
Ben还谈到了一些高级web安全需求,例如方法层的授权、定义方法安全元数据的JSR- 250规格、SpringSecurity方法元数据以及领域的访问控制等。
Unauthenticated access - For all connection modes, services can opt out of the client authorization facility provided by the Relay and allow unauthenticated client access.
匿名访问(UnauthenticatedAccess)——对于所有连接模式,服务可以选择Relay提供的“不经过客户授权”选项并允许匿名访问。
Using Acegi security provides your applications with comprehensive authentication, authorization, instance-based access control, channel security and human user detection capabilities.
使用Acegi安全性可以为应用程序提供全面的身份验证、授权、基于实例的访问控制、通道安全和人工用户检测功能。
XACML (Extensible access control Markup Language) for federated authorization and access control.
联邦授权和访问控制的XACML(可扩展访问控制标记语言)。
The solution should implement some type of authentication system to understand who is asking for a resource and an authorization system to decide whether the access should be granted.
此解决方案应该实现某种类型的身份验证系统来理解谁正在请求一个资源,并实现一个授权系统来决定是否向其授予访问权。
In other words, the database server USES the database privileges associated with APP_USER for all authorization checking and auditing for all database access.
换句话说,数据库服务器使用与APP_USER关联的数据库权限进行所有数据库访问的身份验证和审核。
Introduce a way to authorize resource access in a way that can be directly driven by the application's domain model — specifically by means of authorization for campuses, buildings, rooms, and so on.
引入授权资源访问的方法,使之可以直接受应用程序的域模型驱动——特别是通过授权才能进入校园、大楼、房间等。
应用推荐