AuthZInterop Feedback to Globus - Feb 28-2008 - Minutes

29 Feb 2008
- subject-id attribute of the request subject is NOT mandatory in the XACML or SAML specs. We will use different attribute names for x509 and condor canonical name, to distinguish between them.

- writing policies on pilot job use cases: we envision new policy use cases in the future. For now, we will write policies for 3 use cases: authorize pilot job user, authz user job user, authorize only if pilot job VO is the same as the user job VO.

Authorization Interoperability held on 28 Feb 2008
