Hi Mohammed,
I found this via Google: https://lists.oasis-open.org/archives/xacml/200208/doc00002.doc
In it it says:
urn:oasis:names:tc:xacml:1.0:subject-category:recipient-subject
This identifier indicates
the system entity that will receive the results of the request. Used when it is
distinct from the access-subject.
urn:oasis:names:tc:xacml:1.0:subject-category:intermediary-subject
This identifier indicates
a system entity through which the request was passed. There may be more than
one. No means is provided to specify the order they passed the message.
urn:oasis:names:tc:xacml:1.0:subject-category:requesting-machine
This identifier indicates
a system entity associated with the computer that initiated the request. An example
would be an IPsec identity.
If 200208 relates to the year and month, this is a pretty early document. Perhaps some of the veterans on the list can add comments?
On Tue, Jul 23, 2013 at 5:09 AM, Mohammad Jafari <> wrote:
Hello,
As we are trying to update the XSPA XACML profiles, one of the tasks is to support XACML version 3. I noticed that for “subject” attributes, there are now 4 different categories defined in the core. The mandatory category:
urn:oasis:names:tc:xacml:1.0:subject-category:access-subject
and the optional categories:
urn:oasis:names:tc:xacml:1.0:subject-category:recipient-subject
urn:oasis:names:tc:xacml:1.0:subject-category:intermediary-subject
urn:oasis:names:tc:xacml:1.0:subject-category:requesting-machine
But the core does not provide any definition or discussion about the differences between these categories. I was wondering if anyone can comment about the differences or refer me to a definition so that we can make a better decision on
which category to use for which attributes.
Thanks.
Regards,
Mohammad
--
David Brossard, M.Eng, SCEA, CSTP
Product Manager
+46(0)760 25 85 75
Axiomatics AB
Skeppsbron 40
S-111 30 Stockholm, Sweden
http://www.linkedin.com/companies/536082
http://www.axiomatics.com
http://twitter.com/axiomatics