← Prev in month ← Prev in thread

Re: Minor XACML Spec errata and resource labels

From
Anne Anderson <>
Date
2003-04-21T14:55:00+00:00
ID
Thread
Re: Minor XACML Spec errata and resource labels
Dear Jeff,

Thank you for the erratum.  I have forwarded it to the
xacml-comment mailing list.

I assume, by "resource label", you mean a classification scheme
and a classification value, such as "U.S. Navy Classification
System XYZ" "top secret".  This could be expressed in XACML as an
"Attribute" of the Resource.  The AttributeId could be a URN
indicating the classification scheme, and the AttributeValue
could be the classification value.

Does this satisfy your requirements?

Anne Anderson

On 19 April, Jeff writes: Minor XACML Spec errata and resource labels
>
From: "Jeff" <>
>
To: <>
>
Subject: Minor XACML Spec errata and resource labels
>
Date: Sat, 19 Apr 2003 17:02:54 -0400
 >
> Hi Anne,
 >
> Thanks for all the great XACML work :-)
 >
> There's a minor error on line 1674 (page 44, PolicySet line [071]) of oasis-####-xacml-1.0.pdf: please remove the trailing slash.
 >
> I don't see anything in XACML relating to resource labels (in fact the word label doesn't appear at all in oasis-####-xacml-1.0.pdf!). Resource labels are part of the authorization support in the X.509 standard and are used in several RBAC implementations. Resource labels are useful in enabling resource characteristics (i) to be set on resources and (ii) to form part of access control decisions. I feel sure that you must be aware of this and can only conclude that a PolicySet is intended to act as a resource label (in addition to acting as a policy set!). Is this correct?
 >
 >
> Warmest regards,
 >
> Jeff Lawson
> Cogent Logic
> Toronto, Canada
 > (416) 340 8025
 >
 >
 >
 >
← Prev in month ← Prev in thread