← Prev in month
← Prev in thread
Next in thread →
Next in month →
2.0 Work Item List, v1.25
Colleagues,
The 2.0 Work Item List updated according to discussion and decisions
at the 30 October 2003 XACML TC meeting is attached.
Summary of the changes from the previous version:
7. ConditionReference
STATUS previously stated this had been accepted at the F2F.
STATUS corrected to say this was accepted in general, but that
the proposal needs to be clarified to say references can only
occur to Conditions that are in the same Policy as the reference.
9. Policies referring to hierarchical resources
We are not agreed on this. Some people suggest requiring
all policy references to hierarchical resources be stated
in the form of an XML representation of the resource.
Others suggest defining specific functions or something for
various specific types of hierarchies (e.g. ufs, URLs).
11. XACML Extension Points
We set a due date of 20 Nov 2003 for a proposal for this.
CHAMPIONS are Simon Godik and Michiharu Kudo. Hal Lockhart
has some input from Dave Orchard (BEA) on XML extensions in
general that may or may not be useful in addressing this
work item. Hal will post Dave's input to the list.
22. time-in-range function
Approved in general. Needs detailed proposal.
23. Use XQuery comparison functions for date, time, dateTime
Approved in general. Needs a detailed proposal. New
functions must either be backwards compatible with existing
functions or must have new names that do not conflict with
existing function names (old names can be deprecated in 2.0).
28. Define "current time/date/dateTime" during policy evaluation
Approved specifying that time/date/dateTime ARE constant over
a policy evaluation. Needs detailed proposal.
39. Make Status in the XACML Response optional
Approved in general. Needs detailed proposal.
40. Define a SAML PolicyQuery and PolicyStatement
Description changed to include queries based on a Request
Context, with policies have matching Targets returned.
This will go into an "XACML Profile for Using SAML" rather
than into XACML 2.0.
42. Requests asking for access to multiple elements in a hierarchical
resource
Approved in general requiring XML representation of the resource
being asked about in the <ResourceContent> of the Request. This
does not require any new XACML 2.0 functionality, but the
non-normative Hierarchical Resources section needs to describe
how to do this and that this is the approved way to deal with
requests for multiple elements of a hierarchical resource.
45. Fix AttributeAssignment example in Section 4.2.4.3 (Rule 3)
We assigned Michiharu Kudo as the CHAMPION for this, since he
authored the current example.
46. Status detail for missing attributes
We agreed that we need to define a new "missing attribute"
schema element that can return attribute meta-data (with or
without AttributeValue information) for this. In most
cases, no AttributeValue will be specified. This approach
approved in general.
Two new work items added:
47. New SAML Authorization Decision Query/Response using XACML
TYPE: XACML Profile for Using SAML
STATUS: SAML accepts XACML/OGSA proposal in general (link),
but says XACML should define a SAML extension using the
SAML namespace. We need to verify that SAML 2.0 changes
do not invalidate our proposal. Only Sun(?), Oblix, and
Entrust seem to use the SAML 1.0 version, so will be
deprecated in SAML 2.0.
PROPOSAL: (find link)
CHAMPION: Anne Anderson and Hal Lockhart
48. PAP Interface to a PDP/PRP
Define an interface to a PDP or PRP (Policy Repository Point)
from a PAP for pushing and/or managing policies.
TYPE: XACML Interface Definitions Specification
STATUS: Related to #38,40. Requirements spec needed.
PROPOSAL:
CHAMPION: Tim Moses
--
Anne H. Anderson Email:
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311 Tel: 781/442-0928
Burlington, MA 01803-0902 USA Fax: 781/442-1692
← Prev in month
← Prev in thread
Next in thread →
Next in month →