← Prev in month ← Prev in thread

Re-use of rules in multiple policies

From
<>
Date
2012-02-24T08:34:52+00:00
ID
Thread
Re-use of rules in multiple policies
All, 

Section 2.2 of the core 3.0 spec reads:

278 The <Rule>
279 element contains a Boolean expression that can be evaluated in isolation, but that is not intended to be
280 accessed in isolation by a PDP. So, it is not intended to form the basis of an authorization
281 decision by itself. It is intended to exist in isolation only within an XACML PAP, where it may form the basic unit of
282 management, and be re-used in multiple policies.


How do we envision this re-use of a rule in multiple policies? I don't think the schema has any mechanism for such re-use, like it has for policies through <PolicyIdReference>.


Thanks,
Ray
← Prev in month ← Prev in thread