Holistic Enterprise-Ready Application Security Architecture Framework
HERASAF XACML shall be a comprehensive XACML solution in the future.
So far a fully compliant XACML 2.0 implementation (HERASAF XACML Core) is available.

The XACML Core component is responsible for evaluating XACML 2.0 access requests.
Further it has a lot of useful functionality supporting the evaluation.
See the component page for further information.
This component is available in version 1.0.0-M1 in the downloads section.
The Policy Repository component is responsible for holding the policies for the evaluation.
The current research focus in this direction is about indexing XACML 2.0 policies for accelerating the evaluation process.
This component is not yet available.
The Policy Decision Point (PDP) component is an "endpoint" for components that evaluate an access request.
HERASAF developed two prove of concept web service endpoints in the past.
In the first half of the 2010 it is planned to implement a final web service PDP endpoint during a Bachelor Thesis.
The Policy Administration Point (PAP) component is the part within an XACML framwork that manages the policies.
We think that a PAP must fulfill the following tasks:
Work that is also related to the PAP can be found under Methodology.
In the first half of the 2010 it is planned to do a thesis in the area of conflict detection and resolution.
The Policy Information Point (PIP) component is the part within an XACML framework that resolves missing attributes from further sources (database, ldap, ...).
HERASAF developed a PIP to demonstrate the functionality.
The Policy Enforcement Point (PEP) component is the part within an XACML framework that enforces access control in an application.
HERASAF developed two prove of concept web service endpoints in the past.
There are no future plans currently to implement a PEP component.