Next in thread → Next in month →

RE: [xacml] subject categories

From
Hal Lockhart <>
Date
2013-07-25T18:58:29+00:00
ID
a80b503c-1730-4638-973c-9bf838c1f0e7@default
Thread
RE: [xacml] subject categories
First off, these Subject Categories have been in XACML since version 1.0.

 

There are actually 5. You missed “urn:oasis:names:tc:xacml:1.0:subject-category:codebase”.

 

Their semantics are defined in Appendix B, section B2.

 

Hal

 

From: Mohammad Jafari [mailto:] 
Sent: Monday, July 22, 2013 11:09 PM
To: 
Subject: [xacml] subject categories

 

Hello,

 

As we are trying to update the XSPA XACML profiles, one of the tasks is to support XACML version 3. I noticed that for “subject” attributes, there are now 4 different categories defined in the core. The mandatory category:

urn:oasis:names:tc:xacml:1.0:subject-category:access-subject

and the optional categories:

urn:oasis:names:tc:xacml:1.0:subject-category:recipient-subject

urn:oasis:names:tc:xacml:1.0:subject-category:intermediary-subject

urn:oasis:names:tc:xacml:1.0:subject-category:requesting-machine

 

But the core does not provide any definition or discussion about the differences between these categories. I was wondering if anyone can comment about the differences or refer me to a definition so that we can make a better decision on which category to use for which attributes. 

 

Thanks.

 

Regards,

Mohammad
Next in thread → Next in month →