RE: [xacml] Inputs to rfc822Name-match

From
Tim Moses <>
Date
2004-05-13T12:57:00+00:00
ID
Thread
RE: [xacml] Inputs to rfc822Name-match
MHonArc v2.5.0b2 -->

xacml message

[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]

Subject: RE: [xacml] Inputs to rfc822Name-match

From: Tim Moses <>

To: "''" <>,       Tim Moses <>

Date: Thu, 13 May 2004 09:00:47 -0400

Seth - I am picturing a situation like this ...

A policy is written to apply to the resource "email addresses".  In this
case, the target would contain a resource match with the attribute
designator "resource-id", of type "string" and value "*".

A context request is received containing the resource attribute
"resource-id", of type "RFC 822 name" and the value "".

How can the PDP tell that the policy is applicable?  The resource-ids match,
the data types don't match and "*" isn't obviously an email address.

So, always making the general form the same type as the specific form would
assist matching.  This happens naturally for X.500 names and (I hope) the
other name forms.

All the best.  Tim.