← Prev in month ← Prev in thread
Next in thread → Next in month →

Re: [xacml] BTG comment [WAS: [xacml] Proposed Agenda 10 February2011 TC Meeting]

From
Rich.Levinson <>
Date
2011-02-23T16:57:41+00:00
ID
Thread
Re: [xacml] BTG comment [WAS: [xacml] Proposed Agenda 10 February2011 TC Meeting]
I still think BTG is a  subset of a more general use case. 

Following along with the obligation, my impression was that this must be followed with an ageement to abide by the obligation constraints, e.g. a "promise".  The promise  could act to tell the PDP to change the policy set (in this case to BTG).  With the "state" change the decision is now correct. 

Mike Davis

----- Original Message -----
From: Erik Rissanen <>
To:  <>
Sent: Wed Feb 23 04:42:41 2011
Subject: Re: [xacml] BTG comment [WAS: [xacml] Proposed Agenda 10 February 2011 TC Meeting]

Hi Paul and Mike,

I agree, but isn't this exactly what David is proposing? That is how I 
understand it, at least for the "PEP state" mode. The other alternative 
with the PDP maintaining state is something I don't think is a good idea.

To make David's proposal better, it needs:

- Drop the PDP state approach since this goes against the capability of 
the XACML model which does not have a state built in.

- Define identifiers for at least the BTG obligation/advice (advice is 
better, but for XACML 2.0 an obligation needs to be used), the action-id 
for breaking glass (as well as giving some kind of direction of what the 
BTG request should look like in relation to resources being accessed).

- It would be nice with a full, worked through example.

Best regards,
Erik

On 2011-02-23 05:06, Davis, John M. wrote:
← Prev in month ← Prev in thread
Next in thread → Next in month →