Authorization
Authorization refers to granting or denying access to specific resources based on the requesting user’s identity. This step is performed after a user is identified through authentication. Authorization is usually performed through access control lists, which associate user identities with specific rights. Authorization includes information such as a user’s group membership, user policies, and other information that determines what level of access that user has to computer or network resources.
It is important to note that the ability to make correct authorization decisions rests solely on a solid authentication mechanism. The only way that a correct authorization decision can be made is if the user has already been correctly authenticated. Authorization ceases to work if the authentication method can’t be trusted. If the authentication mechanism returns a false identity to the authorization mechanism, then there is no way for the authorization mechanism to correct this, and it can allow an attacker to masquerade as a legitimate user.
As a result, solid authorization mechanisms depend on an effective authentication system. Systems that depend on weak authentication will fail, no matter how sophisticated the authorization may be. An example is the standard NFS protocol. NFS requires servers to trust the clients, since users are “authenticated” by a plaintext UID sent by the client. Clearly, this mechanism makes it trivial to spoof any username on an NFS server. The ease ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access