Pros and cons of attribute-based access control

Encoding attributes in certificates has its own set of pros and cons. On one hand, all the information associated with an identity is encoded in the certificate, thus decisions can be made based on attributes. On the other hand, if an attribute has to be updated, for example, a user moves to a different department, the existing certificate must be revoked, and a new certificate has to be issued with a new set of attributes.

