Re: [xacml] Current Formalism

From
Bill Parducci
Date
2002-02-04T17:29:00+00:00
ID
Thread
Re: [xacml] Current Formalism
correct, however, this must be done in describable fashion so that the
overall result is deterministic. to me that means that the
default/base/widget/magic policy must be a component of the XACML scope.
(that way anne can have true+n/a=permit and i can have true+n/a=deny
evaluate within the same expressive framework :o)

b

Polar Humenn wrote:
> An ApplicablePolicy evaluates to True, False, or Inapplicable.
>
> It is the job of the PDP to map these values to Permit, Deny, or
> Indeterminate, which is an adminstrative policy of the PDP.
>
> The most likely would be,
>
> Policy
Result
>

------

------
> True
Permit
> False
Deny
> Inapplicable
Indeterminate, or a "default" of Permit, Deny
>
> -Polar
>
>