Re: [xacml] IP Address comparisons

From
Steven Legg <>
Date
2013-10-04T00:14:24+00:00
ID
Thread
Re: [xacml] IP Address comparisons
Hi Hal,

I don't think that port ranges and wildcards belong in the ipAddress and dnsName
data-types if we are serious about defining equality functions for these data-types.
An equality function is normally expected to have the property of transitivity
(A=B and B=C implies A=C), otherwise things like set operations can produce
bizarre results. Port ranges and wildcards break transitivity.

X.500, and LDAP by association, require equality matching rules to be transitive
and also make a distinction between attribute value syntax and assertion value
syntax. I think this is a good model to follow. Wildcards and the like only
ever appear in assertion values. Note that the XACML rfc822Name-match function
fits this model too in that the "assertion" value is a string rather than an
rfc822Name because it supports wildcarding by omitting fields and this has the
effect of making the assertion string invalid as an rfc822Name.

The analogous situation for ipAddress and dnsName is to exclude port ranges and
wildcards (perhaps also masks) from values of these data-types, but allow ranges
and wildcards in assertion string arguments of special, non-transitive match
functions. These match functions would be in addition to the ipAddress-equal and
dnsName-equal functions that take two values of the relevant syntax and know
nothing about ranges and wildcards.

Without port ranges and wildcards it becomes straightforward to define an
ordering relation for ipAddress and dnsName, and with that, functions for
<, >, <= and >= comparisons. These functions could satisfy some of the use
cases for the special match functions allowing us to keep the special match
functions fairly simple.

On the question of whether the singular port number should be part of the
ipAddress and dnsName data-types or separate, I think either way is workable.
However, if a port number is an optional part of these data-types, then an
ipAddress/dnsName without a port number should not ever be considered equal
to an ipAddress/dnsName with a port number, otherwise we stray away from
transitivity. For ordering purposes, an ipAddress/dnsName without a port number
could be defined to be less than the same ipAddress/dnsName with a port number.

Regards,
Steven

On 2/10/2013 3:39 AM, Hal Lockhart wrote: