#XACML #SAML Profile Version 2.0 Committee Specification 02 published

OASIS is pleased to announce the approval and publication of a new Committee Specification by the members of the OASIS eXtensible Access Control Markup Language (XACML) TC:

XACML SAML Profile Version 2.0
Committee Specification 02
19 August 2014


This specification defines a profile for the integration of the OASIS Security Assertion Markup Language (SAML) Version 2.0 with all versions of XACML. SAML 2.0 complements XACML functionality in many ways, so a number of somewhat independent functions are described in this profile:

1) use of SAML 2.0 Attribute Assertions with XACML, including the use of SAML Attribute Assertions in a SOAP Header to convey Attributes that can be consumed by an XACML PDP

2) use of SAML to carry XACML authorization decisions, authorization decision queries, and authorization decision responses

3) use of SAML to carry XACML policies, policy queries, and policy query responses

4) use of XACML authorization decisions or policies as Advice in SAML Assertions

5) use of XACML responses in SAML Assertions as authorization tokens.

Particular implementations may provide only a subset of these functions.

Members of the XACML SAML Profile Version 2.0 requested a Special Majority Vote to approve this specification as a Committee Specification. The specification had been released for public review as required by the TC Process. The vote to approve as a Committee Specification passed, and the approved CS02 is now available online in the OASIS Library as referenced above.

Our congratulations to the TC on achieving this milestone.

