<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Analyzing Identity</title>
	<atom:link href="http://analyzingidentity.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://analyzingidentity.com</link>
	<description>Gerry Gebel&#039;s Identity Industry Insights</description>
	<lastBuildDate>Fri, 18 Mar 2011 15:28:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Take 2, talking authZ with Gunnar by Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity</title>
		<link>http://analyzingidentity.com/2011/01/28/take-2-talking-authz-with-gunnar/#comment-163</link>
		<dc:creator><![CDATA[Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity]]></dc:creator>
		<pubDate>Fri, 18 Mar 2011 15:28:58 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=100#comment-163</guid>
		<description><![CDATA[[...] to my colleagues, David Brossard and Pablo Giambiagi, for their input. You can also find part 1 and part 2 of the conversation on this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] to my colleagues, David Brossard and Pablo Giambiagi, for their input. You can also find part 1 and part 2 of the conversation on this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Anywhere Application Architecture by Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity</title>
		<link>http://analyzingidentity.com/2010/06/08/the-anywhere-application-architecture/#comment-162</link>
		<dc:creator><![CDATA[Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity]]></dc:creator>
		<pubDate>Fri, 18 Mar 2011 15:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=56#comment-162</guid>
		<description><![CDATA[[...] talked previously about the XACML Anywhere Architecture where a callback from a Cloud Provider queries PDP; this would enable the Cloud Provider to get the [...]]]></description>
		<content:encoded><![CDATA[<p>[...] talked previously about the XACML Anywhere Architecture where a callback from a Cloud Provider queries PDP; this would enable the Cloud Provider to get the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Talking authorization with Gunnar Peterson by Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity</title>
		<link>http://analyzingidentity.com/2010/12/15/talking-authorization-with-gunnar-peterson/#comment-161</link>
		<dc:creator><![CDATA[Take 3, talking authZ and TOCTOU with Gunnar &#171; Analyzing Identity]]></dc:creator>
		<pubDate>Fri, 18 Mar 2011 15:28:40 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=96#comment-161</guid>
		<description><![CDATA[[...] also to my colleagues, David Brossard and Pablo Giambiagi, for their input. You can also find part 1 and part 2 of the conversation on this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] also to my colleagues, David Brossard and Pablo Giambiagi, for their input. You can also find part 1 and part 2 of the conversation on this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Take 2, talking authZ with Gunnar by Tweets that mention Take 2, talking authZ with Gunnar « Analyzing Identity -- Topsy.com</title>
		<link>http://analyzingidentity.com/2011/01/28/take-2-talking-authz-with-gunnar/#comment-147</link>
		<dc:creator><![CDATA[Tweets that mention Take 2, talking authZ with Gunnar « Analyzing Identity -- Topsy.com]]></dc:creator>
		<pubDate>Fri, 28 Jan 2011 14:24:04 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=100#comment-147</guid>
		<description><![CDATA[[...] This post was mentioned on Twitter by Paul Madsen, 4403 and Kenji Urushima, Gerry Gebel. Gerry Gebel said: Cross posted take 2 of XACML conversation w/ @oneraindrop http://bit.ly/hp0sao [...]]]></description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Paul Madsen, 4403 and Kenji Urushima, Gerry Gebel. Gerry Gebel said: Cross posted take 2 of XACML conversation w/ @oneraindrop <a href="http://bit.ly/hp0sao" rel="nofollow">http://bit.ly/hp0sao</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Talking authorization with Gunnar Peterson by Take 2, talking authZ with Gunnar &#171; Analyzing Identity</title>
		<link>http://analyzingidentity.com/2010/12/15/talking-authorization-with-gunnar-peterson/#comment-145</link>
		<dc:creator><![CDATA[Take 2, talking authZ with Gunnar &#171; Analyzing Identity]]></dc:creator>
		<pubDate>Fri, 28 Jan 2011 13:41:08 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=96#comment-145</guid>
		<description><![CDATA[[...] Analyzing Identity Gerry Gebel&#039;s Identity Industry Insights      &#171; Talking authorization with Gunnar&#160;Peterson [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Analyzing Identity Gerry Gebel&#039;s Identity Industry Insights      &laquo; Talking authorization with Gunnar&nbsp;Peterson [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Dazza Greenwood</title>
		<link>http://analyzingidentity.com/about/#comment-144</link>
		<dc:creator><![CDATA[Dazza Greenwood]]></dc:creator>
		<pubDate>Wed, 26 Jan 2011 04:56:20 +0000</pubDate>
		<guid isPermaLink="false">#comment-144</guid>
		<description><![CDATA[Great information about XACML.  Thanks very much.
 - Dazza]]></description>
		<content:encoded><![CDATA[<p>Great information about XACML.  Thanks very much.<br />
 &#8211; Dazza</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authorization Performance Myth Busting by ggebel</title>
		<link>http://analyzingidentity.com/2010/04/30/authorization-performance-myth-busting/#comment-128</link>
		<dc:creator><![CDATA[ggebel]]></dc:creator>
		<pubDate>Fri, 03 Dec 2010 16:41:02 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=22#comment-128</guid>
		<description><![CDATA[Chi - you are right that querying whether a user has access to large numbers of assets is a bit challenging for XACML-based systems. However we have an interesting way of addressing this and you can contact me at gerry-at-axiomatics-dot-com to learn about it.

Gerry]]></description>
		<content:encoded><![CDATA[<p>Chi &#8211; you are right that querying whether a user has access to large numbers of assets is a bit challenging for XACML-based systems. However we have an interesting way of addressing this and you can contact me at gerry-at-axiomatics-dot-com to learn about it.</p>
<p>Gerry</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authorization Performance Myth Busting by Chi</title>
		<link>http://analyzingidentity.com/2010/04/30/authorization-performance-myth-busting/#comment-123</link>
		<dc:creator><![CDATA[Chi]]></dc:creator>
		<pubDate>Fri, 26 Nov 2010 05:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=22#comment-123</guid>
		<description><![CDATA[One problem I need to solve is user searching/browsing in a repository. For example, if the repository has 100k+ assets (or even millions), and we employ a faceted search engine like Apache Solr, how can we get around this performance problem? Note that Solr faceted search requires looking through all the assets in the repository via its indexes? Even without Solr, if you just want to offer paged search results, you will still need to iterate through the assets. Is the answer simply: no it cannot be done?]]></description>
		<content:encoded><![CDATA[<p>One problem I need to solve is user searching/browsing in a repository. For example, if the repository has 100k+ assets (or even millions), and we employ a faceted search engine like Apache Solr, how can we get around this performance problem? Note that Solr faceted search requires looking through all the assets in the repository via its indexes? Even without Solr, if you just want to offer paged search results, you will still need to iterate through the assets. Is the answer simply: no it cannot be done?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PayPal Selects Axiomatics Access Management Solution by Pat Patterson</title>
		<link>http://analyzingidentity.com/2010/11/18/paypal-selects-axiomatics-access-management-solution/#comment-121</link>
		<dc:creator><![CDATA[Pat Patterson]]></dc:creator>
		<pubDate>Sun, 21 Nov 2010 17:02:24 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=92#comment-121</guid>
		<description><![CDATA[Congratulations, Gerry - it&#039;s good to see XACML getting traction!]]></description>
		<content:encoded><![CDATA[<p>Congratulations, Gerry &#8211; it&#8217;s good to see XACML getting traction!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Discussing XACML with Travis by Travis Spencer</title>
		<link>http://analyzingidentity.com/2010/10/06/discussing-xacml-with-travis/#comment-57</link>
		<dc:creator><![CDATA[Travis Spencer]]></dc:creator>
		<pubDate>Fri, 15 Oct 2010 06:26:39 +0000</pubDate>
		<guid isPermaLink="false">http://analyzingidentity.com/?p=88#comment-57</guid>
		<description><![CDATA[Thanks for the response to my blog post, Gerry! You made some good points and gave me a lot of food for thought. 

I certainly agree that there are cases where users will need full access to the power of XACML and times when they will accept that a high level of sophistication is needed to work w/ it directly, especially if this is contained in a single upfront investment in the creation of slow changing policies. For some scenarios that I have in mind, however, policy authoring  is an ongoing business function which is why I said a simplified, domain-specific façade atop XACML is important. 

Also, I completely agree that new wire protocols be defined in a collaborative environment where all stakeholders have a voice. This open dialog is one aspect of this that I&#039;m eager to continue at IIW, RSA, and other upcoming conferences. Perhaps I&#039;ll even join OASIS to lend a hand in the definition of these profiles :-)

Thanks again, Gerry!]]></description>
		<content:encoded><![CDATA[<p>Thanks for the response to my blog post, Gerry! You made some good points and gave me a lot of food for thought. </p>
<p>I certainly agree that there are cases where users will need full access to the power of XACML and times when they will accept that a high level of sophistication is needed to work w/ it directly, especially if this is contained in a single upfront investment in the creation of slow changing policies. For some scenarios that I have in mind, however, policy authoring  is an ongoing business function which is why I said a simplified, domain-specific façade atop XACML is important. </p>
<p>Also, I completely agree that new wire protocols be defined in a collaborative environment where all stakeholders have a voice. This open dialog is one aspect of this that I&#8217;m eager to continue at IIW, RSA, and other upcoming conferences. Perhaps I&#8217;ll even join OASIS to lend a hand in the definition of these profiles <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Thanks again, Gerry!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

