RE: [xacml] MAD conceptual model

From
Tyson, Paul H <>
Date
2009-10-16T15:58:04+00:00
ID
Thread
RE: [xacml] MAD conceptual model
Attached version has a few corrections and clarifications.

--Paul 

> -----Original Message-----
> From: Tyson, Paul H 
> Sent: Friday, October 16, 2009 09:59
> To: 
> Subject: [xacml] MAD conceptual model
> 
> Attached find proposed description of conceptual model for 
> producing single authorization decision requests from a 
> multiple authorization decision (MAD) request.
> 
> This would replace some content in sections 2.1, 2.2, 2.3.
> 
> I came up with a few questions and concerns:
> 
> 1. I still don't like the idea of mutable resource-ids.  
> Either the original request should have something like 
> "resource-selector", or the resulting context should have 
> "decision-node-id" or something.  But then the problem is, 
> how does the PEP request the resource-id to be returned 
> (using "IncludeInResult")?  We might have to specify some 
> built-in semantics to handle this.
> 
> 2. This does not specify how the xpathExpression resource-id 
> for individual resources will be constructed.  The TC is 
> still discussing whether to specify this, and if so, what the 
> form should be.  In any case, it seems necessary to say 
> something about the namespace binding context that will be 
> used for name prefixes.  Default might be to use the 
> namespace binding context represented by the union of the 
> contexts in <Content> children, but this is not specified. 
> One way to facilitate regexp matching on xpath strings would 
> be to allow policies and/or requests to specify a namespace 
> binding context.
> 
> 3. scope=EntireHierarchy is out of place here.  Consider 
> moving Section
> 3 to hierarchical profile.  The conceptual model and expected 
> results are different than the other multiple authorization 
> decision modes.  The "multiple" processing only takes place 
> internally--a single decision is expected (possibly 
> multiplied by additional subjects or actions).
> 
> Regards,
> --Paul
>