RE: [EXTERNAL] [xacml] Re: [xacml-comment] FW: Question with the XACML-REST namespace

From
Davis, John M. <>
Date
2018-09-18T22:13:18+00:00
ID
Thread
RE: [EXTERNAL] [xacml] Re: [xacml-comment] FW: Question with the XACML-REST namespace
Hal,

 

No project yet but something that we would like to see and we are an Axiomatics shop.

 

 

John âMikeâ Davis

VHA Security Architect

760-632-0294

 

 

 

 

 

 

From:  [mailto:]
On Behalf Of David Brossard

Sent: Tuesday, September 18, 2018 12:57 PM

To: Harold Lockhart <>; DANGERVILLE Cyril <>

Cc: xacml <>; 

Subject: [EXTERNAL] [xacml] Re: [xacml-comment] FW: Question with the XACML-REST namespace

 

Here what I can find:

Axiomatics Policy Server implements the REST interface

We know from Cyril (in cc) that AuthZForce does too

ViewDS? Steven I believe you do, right?

According to Google so does Balana (WSO2)

EU SUNFISH Project

Oracle Platform Security Services (OPSS) 

That's all I could find. I will pass on the information to our development team. I doubt it's a major change. Also, it does not play an active part in the runtime authorization flow. I would be OK with the change.

 

David.

 

On Tue, Sep 18, 2018 at 2:51 PM Hal Lockhart <> wrote:

I need to hear from as many organizations as possible who are implementing the REST Profile. As you can see below, the current namespace is not in accord
 with Naming Directives. The question is: is it too late to change this?

 

If you are not comfortable answering publically for some reason, you can respond directly to the chairs.

 

Hal

 

 

From: Chet Ensign <>

Sent: Tuesday, September 18, 2018 12:58 PM

To: Hal Lockhart <>; bill parducci <>

Cc: Paul Knight <>

Subject: Question with the XACML-REST namespace

 

Hi Bill, hi Hal, 

 

Paul came across the namespace for the XACML-REST specification yesterday and realized that it doesn't conform to the format in use. 

 

The namespace is

http://docs.oasis-open.org/ns/xacml/relation. Per the Naming Directives, the form we'd use would be

http://docs.oasis-open.org/xacml/ns/relation.

 

Paul noted however that the namespace appears to be in use in a lot of implementations. He did a search in Google for "ns/xacml/relation" and got 114 hits. 

 

So we'll leave it as is unless you tell us that it doesn't matter. If changing it won't break anything, we'll update it. But if it cause headaches and work for your user community,
 then we'll leave it alone. 

 

Can you just confirm to us either that we should leave it as is or that we can go ahead and change it, I'd appreciate it. We'll then have the issue documented for future publications. 

 

Thanks much, 

 

--

/chet 

----------------

 

Looking forward to Borderless
 Cyber 2018, 3-5 Oct, Washington, D.C.

Organized by The World Bank, OASIS, and Georgetown University

 

Chet Ensign

Chief Technical Community Steward

OASIS: Advancing open standards for the information society

http://www.oasis-open.org

Primary: +1 973-996-2298

Mobile: +1 201-341-1393 

 

-- 

David Brossard

VP of Customer Relations

+1 312 774-9163

+1 502 922 6538

+46(0)760 25 85 75

 

Axiomatics | 525 W. Monroe Suite 2310 | Chicago
 60661

Support: https://support.axiomatics.com 

Web: http://www.axiomatics.com

Axiomatics Blog | Events | Resources,
 Webinars & Whitepapers

Connect with us on LinkedIn | Twitter | Google
 + | Facebook | YouTube | Stackoverflow