Re: [xacml] F2F Agenda Topics

From
rich levinson <>
Date
2011-06-20T15:40:08+00:00
ID
Thread
Re: [xacml] F2F Agenda Topics
This is a capability we (DHS and others) are very interested in.
Whether it is an XACML standards issue or not is debatable (vs. a
"tools" issue) but I note that a good deal of the overall Security TC
work is based on a unifying architectural model of access control that
is beyond the scope of the SAML or XACML standards themselves. So I hope
we can identify someone to tackle the requirement . . .

Regards,
Martin


Martin F. Smith
Director, National Security Systems
US Department of Homeland Security
NAC 19-204-47
(202) 447-3743 desk
(202) 441-9731 mobile


-----Original Message-----
From: xacml-return-2710-martin.smith=
[mailto:xacml-return-2710-martin.smith=] On
Behalf Of Tyson, Paul H
Sent: Friday, June 17, 2011 5:35 PM
To: ; ; 
Subject: RE: [xacml] F2F Agenda Topics

This sounds like a very strange business case, and I don't see how XACML
can help.

It does not appear to be a rational model for policy development if
independent groups are making rules concerning potentially overlapping
instances of subject/resource/action.  That is anarchy, not federation.

And even if some enterprises find it useful to develop policies that
way, the PDP implementation should allow specifying one of the existing
policy-combining algorithms (or a custom one) at the notional "root" of
the policy tree.

Regards,
--Paul