This is a capability we (DHS and others) are very interested in.
Whether it is an XACML standards issue or not is debatable (vs. a
"tools" issue) but I note that a good deal of the overall Security TC
work is based on a unifying architectural model of access control that
is beyond the scope of the SAML or XACML standards themselves. So I hope
we can identify someone to tackle the requirement . . .
Regards,
Martin
Martin F. Smith
Director, National Security Systems
US Department of Homeland Security
NAC 19-204-47
(202) 447-3743 desk
(202) 441-9731 mobile
-----Original Message-----
From: xacml-return-2710-martin.smith=
[mailto:xacml-return-2710-martin.smith=] On
Behalf Of Tyson, Paul H
Sent: Friday, June 17, 2011 5:35 PM
To: ; ;
Subject: RE: [xacml] F2F Agenda Topics
This sounds like a very strange business case, and I don't see how XACML
can help.
It does not appear to be a rational model for policy development if
independent groups are making rules concerning potentially overlapping
instances of subject/resource/action. That is anarchy, not federation.
And even if some enterprises find it useful to develop policies that
way, the PDP implementation should allow specifying one of the existing
policy-combining algorithms (or a custom one) at the notional "root" of
the policy tree.
Regards,
--Paul