Re: [xacml] Proposed semantics for operations involving INDETERMI NATE
> Well, our current model, in your example, policies 1,2,3, and 5 would say > Indeterminate, while #4 says Permit. However, if #5, by some crystal ball, > may return a Deny. If that is really your intent, then you need to wrap > the combination of policies with the Bill Parducci Policy Combinator which > only gives yields Permit if every policy evaluates to Permit. my combinator permits NO ONE -- the ultimate in security!! :o) b