← Prev in month ← Prev in thread
Next in thread → Next in month →

Updated XACML 2.0 Work Item Index, Version 1.41

From
Anne Anderson <>
Date
2004-03-02T19:11:00+00:00
ID
Thread
Updated XACML 2.0 Work Item Index, Version 1.41
MHonArc v2.5.0b2 -->
















xacml message






[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]








Subject: Updated XACML 2.0 Work Item Index, Version 1.41




From: Anne Anderson <>
To: XACML TC <>
Date: Tue, 02 Mar 2004 14:24:00 -0500






Colleagues,

This list includes the open items from the XACML 2.0 Work Item
Index.  Some of these are targetted for profiles that are not
tied to XACML 2.0.  A full updated Work Item Index, showing open
and closed items, is attached.

WI#2. Location Information
   PROFILE: Location Information Profile
   STATUS: Open issues.
   ACTION: Seth to produce revised proposal.

WI#7. ConditionReference
   STATUS: Open issues.
   ACTION: Need final consensus proposal from proponents.

WI#9. Policies referring to hierarchical resources
   STATUS: Open issues.
   ACTION: Anne to look at WS-ResourceDescriptionFramework to see
    if it handles hierarchical resources appropriately, otherwise
    revise CURRENT.

   [NOTE:WI#9 "Policies referring to hierarchical resources" is
    different from WI#42 "Requests asking for access to multiple
    elements in a hierarchical resource".

    WI#9 is about how a policy can protect all nodes in a subtree
    of a hierarchy without having to specify a separate policy
    condition for each.

    WI#42 is about how a single request can ask for access to
    multiple nodes in a hierarchy, getting back multiple
    responses (which XACML already supports).  XACML already
    supports this functionality for XML documents using the
    urn:oasis:names:tc:xacml:1.0:resource:scope AttributeId
    described in Section 7.8 (Immediate,Children, Descendants),
    but not for hierarchical resources in general.]

WI#10. Parameters for Combining Algorithms
   STATUS: Open.  Re-opened with proposal from WI#11 on 12 Feb.
   ACTION: are we ready to vote on this?

WI#13. Optional Target Elements
   STATUS: Included in 2.0 draft 05 Section 5.5.  Add note on
   ACTION: Tim to add note on "<Subjects></Subjects> = false" to
    Draft 06.

WI#18. Obligations in Rules
   STATUS: Open issues.
   ACTION: Polar wants to try to develop an alternative approach.

WI#23. Use XQuery comparison functions for date, time, dateTime
   STATUS: Approved in general 30 Oct 2003.  Waiting for new XML
    Schema definitions of time, etc.  How long are we willing to
    wait?
   ACTION: Seth to provide update.

WI#29. Policy Authority Delegation
   PROFILE: Administration Policy Profile
   STATUS: Open issues.
   ACTION: Need to review Tim's new Use Cases document.

WI#31. Attribute Issuer as Subject
   STATUS: Open issues.  
   ACTION 12 Feb: Depends on Admin Policy model.  Request use
    cases from those interested in this item.  Plan to agree on a
    model at the next F2F.  This will require people to do
    homework ahead of time.

WI#32. Standardize naming to specify rules for requestor's authz policy
   PROFILE?
   STATUS: Open issues.
   ACTION: need Frank to explain his use case in a
    teleconference, not just by e-mail.

WI#33. XACML wsdl/porttype definition for <Req>/<Resp> exchange
   PROFILE: WSDL Profile
   STATUS: Needs detailed proposal.

WI#34. porttype/operations to ask for required attributes
   PROFILE: WSDL Profile
   STATUS: Open issues.

WI#36. Check for requester authorized to ask for authz decision
   PROFILE?
   STATUS: Open issues.  For F2F.
   ACTION: This should be an aspect of our Administrative Policy,
    and should be resolved at the next F2F as part of the overall
    Administrative Policy framework.

WI#37. Multiple <AttributeValue> elements for single <Attribute> in Request
   STATUS: Open issues.  Included in 2.0 draft 05.  Additional
    edits needed in response to Rebekah's questions.  Current
    discussion on e-mail ist.
   ACTION: Tim to include additional edits in response to
    Rebekah's questions.

WI#40. Define a SAML PolicyQuery and PolicyStatement
   PROFILE: XACML SAML Profile
   STATUS: Open.
   ACTION: Anne updating SAML Profile.

WI#42. Requests asking for access to multiple elements in a hierarchical resource
   STATUS: Accepted in general for 2.0 30 Oct 2003.  Resolution
    is a separate WI#58.
   ACTION: Needs to be explained in specification in
     non-normative Hierarchical Resources section.

WI#43. Examine interactions between approved work items
   STATUS: Open.  Waiting for resolutions to all WI's.

WI#46. Status detail for missing attributes
   STATUS: Open.  Need to define a new "missing attribute" schema
   ACTION 12 Feb 2004: Seth to produce missing attribute schema.

WI#47. New SAML Authorization Decision Query/Response using XACML
   PROFILE: XACML SAML Profile
   STATUS: SAML accepted XACML/OGSA proposal in general.
   ACTION: Anne updating SAML Profile.

WI#48. PAP Interface to a PDP/PRP
   PROFILE: XACML Interface Definitions Specification
   STATUS: Open.  Related to #38,40.  Requirements spec needed.
   ACTION: Tim to produce requirements spec.

WI#52. New section explaining not backwards compatible and listing changes
   STATUS: Awaiting detailed proposal once other WI's resolved.
   ACTION: Bill Parducci has volunteered.

WI#53. Drop <Function> element
   STATUS: Will this change with the new
    reference proposals for WI#7?  No plans currently to change
    or eliminate <Function>.
   ACTION: Tim will add additional clarifying text to the
    description of <Function> explaining how and why it is used.

WI#54. Is resource-id required?
   STATUS: Voted to make resource-id optional 8 Jan 2004.
   ACTION: Tim to make optional in next draft.

WI#55. Converge SAML and XACML Attribute schema definitions
   PROFILE: Some of this could go into XACML SAML Profile.
   STATUS: Open.  Still under discussion.  SAML has not frozen
   ACTION: continue discussion with SAML people; Anne updating
    SAML Profile.

WI#58. Standard hierarchy schemas
   TYPE: Interoperability.  Could be separate profile, but if a
    single standard schema for hierarchies developed, it should
    be part of 2.0.
   STATUS: Open.
   ACTION: need to be able to associate attributes such as owner
    with nodes.  Look at W3C ResourceDescriptionFramework, in case
    it offers anything.  We don't know if this applies, but the
    name sounds promising.  Anne looking into this.

WI#59. Define standard "role" subject attribute
   PROFILE: XACML Profile for Role Based Access Control.
   STATUS: 12 Feb 2004 FG recommended including in next RBAC
    draft.  Need vote to approve RBAC Version 02 as Committee
    Draft with this.
   PROPOSAL:
     http://lists.oasis-open.org/archives/xacml/200401/msg00038.html
   ACTION: Vote.

WI#60. Define standard "purpose" attributes
   PROFILE: Privacy Profile
   STATUS: Open.
     http://www.oasis-open.org/committees/download.php/5589/oasis_xacml_v2.0_privacy-profile_moses_01.zip [Draft profile]
   CHAMPION: Tim Moses
   ACTION: Study Tim's draft.

WI#61. Negating TargetMatch
   STATUS: Not yet discussed.
   CHAMPION: Seth Proctor

WI#62. New string functions
   STATUS: Not yet discussed
   CHAMPION: Seth Proctor

Anne
-- 
Anne H. Anderson             Email: 
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311     Tel: 781/442-0928
Burlington, MA 01803-0902 USA  Fax: 781/442-1692
← Prev in month ← Prev in thread
Next in thread → Next in month →