Re: [xacml] New Issue#83: CORE ERRATA: error in 7.15.3 Missing attributes

From
Rich Levinson <>
Date
2007-06-28T15:08:50+00:00
ID
Thread
Re: [xacml] New Issue#83: CORE ERRATA: error in 7.15.3 Missing attributes
I am correcting this in 3.0 and the errata. I changed it to "may result"
since it is not certain the end result will be indeterminate. There
could be another policy which works and is selected by the policy
combining algorithm. I also added "if the designator or selector has the
MustBePresent XML attribute set to true", to not confuse with empty bags.

While looking into this I think I have found another minor error. In
section 5.42 it says:

---

If the node selected by the specified XPath expression is not one of
those listed above (i.e. a text node, an attribute node, a processing
instruction node or a comment node), then the result of the enclosing
*/policy/* SHALL be "Indeterminate" with a StatusCode value of
"urn:oasis:names:tc:xacml:1.0:status:syntax-error".

---

I think this is incorrect. It should be that the value of the attribute
selector element is indeterminate, not the enclosing policy. The value
of the policy (or rule actually) would depend on the combining
algorithm, which could find another policy which it prefers.

Do you agree with me?

Regards,
Erik


Anne Anderson - Sun Microsystems wrote: