MHonArc v2.5.0b2 -->
xacml message
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
--
[Date Index]
| [Thread Index]
| [List Home]
Subject: Re: [xacml] Inputs to rfc822Name-match
From: Bill Parducci <>
To: "'XACML'" <>
Date: Thu, 13 May 2004 06:49:57 -0700
perhaps we could create a 'mask' that would the name to conform, but provide for
a range of values to match? (ala IP masking)
in other words the resource could be '' with a mask of '@bar.com' and
any request of type rfc822 containing the domain '@bar.com' would result in a
match. it is kind of a long way around to do the same thing i think tim is
asking for but it leaves the rfc822 names valid and extends by allowing the
[soon to be omnipotent ;o] context handler to match a range via an *extension*
of the rfc822 names.
i dunno, just thinking out of the box. (i definitely think there is a valid use
case for this).
b
Tim Moses wrote:
> Seth - I am picturing a situation like this ...
>
> A policy is written to apply to the resource "email addresses". In this
> case, the target would contain a resource match with the attribute
> designator "resource-id", of type "string" and value "*".
>
> A context request is received containing the resource attribute
> "resource-id", of type "RFC 822 name" and the value "".
>
> How can the PDP tell that the policy is applicable? The resource-ids match,
> the data types don't match and "*" isn't obviously an email address.
>
> So, always making the general form the same type as the specific form would
> assist matching. This happens naturally for X.500 names and (I hope) the
> other name forms.
>
> All the best. Tim.
>
>