On 11 October, Hal Lockhart writes: [xacml] Question about Anonymous Access Subject?
> Is there a cannonical way to represent an anonymous access subject in the
> Request Context? This seems to me to be an extremely common case that should
> be described in the spec. (My preference would be to leave out the access
> subject entirely, but I see that it is mandatory)
Yes, there is a canonical way. The sequence of Attributes under
<Subject> is minOccurs=0, so you can have a Request Context in
which the one <Subject> element has no Attributes (such as no
subject-id).
Anne
--
Anne H. Anderson Email:
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311 Tel: 781/442-0928
Burlington, MA 01803-0902 USA Fax: 781/442-1692