Description
This is Working Draft 5 of the Web Services Profile of XACML (the old name was "XACML profile for Web-services (WSPL)", and has been changed to match new conventions). It specifies ways to use XACML in the context of Web Services for authorization, access control, and privacy policies.
This new profile differs from the previous version in addressing individual authorization, access control, and privacy policy assertions, rather than generic Web Services policies or association of such policies with policy targets. This new profile also specifies use of XACML authorization decisions as authorization tokens in SOAP message headers, and conveyance of Attributes for use by an XACML Context Handler in SOAP message headers.