Re: [xacml] New core and multiple resource profile and hierarchical

From
Daniel Engovatov <>
Date
2009-03-10T20:55:15+00:00
ID
EMEWEMEW2_DELIMl29Fmu3e280be10f8d9fd5d0c815,,6BE3E8A6-DBCD-4FF2-A89F-AA308
Thread
Re: [xacml] New core and multiple resource profile and hierarchical
>
> What it MUST include however, is the forest model. The reason for  
> this is that the existing profile gives:

Several weeks into this discussion, I still have not seen a single  
concrete use case that warrants this.

> As the profile stands now, with a choice of general DAG and  
> concrete URI, I believe many customers will be unknowingly led into  
> an insecure DAG, when a perfectly reasonable secure forest could be  
> shown to be a clear alternative, with the extra cost, of course, of  
> maintaining the membership in the original hierarchies, which is  
> necessary to generalize the URI scheme.
>

I still have not seen a single compelling  example why DAG is  
"insecure" in any form.  Applicable policy is entirely explicit, and  
easy to analyze.


Daniel;