OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: RE: XACML TC Charter Revision - Strawman


Sorry to be slow on this, but there is another issue I think we need to consider and include or explicitly reject. I will describe this informally because it is easier to express that way and I hope will be easier to understand. If we get some consensus we can worry about more precise expression. Since this bears on the use of XACML by SAML, I have cross posted this. As I understand it the current scope of the XACML schema is to express: 1. Some policy is this . SAML is interested in using XACML as a means of expressing a Authorization Policy Decisions. In other words something like: 2. The result of evaluating this is TRUE (or FALSE) It seems to me that under the current charter for XACML, this should work. However, in order to do this, SAML needs to be able to make a request for this to be done. Presumably, making the request does not require knowing what policies apply. Therefore it needs to be possible to say: 3. Please evaluate the policies that apply to target X. Here are some inputs that may be needed for this decision. [The PDP will fill in any missing values, either by observing them for itself (e.g. date/time) or by using default values (e.g. unauthenticated subject).] It seems to me that XACML could help with this. For example, XACML will certainly have to define a generalized syntax for expressing the name of a target. Also, if you can say: a) True if signinglimit > $5000 Then similar syntax could be used to express: b) Current value of signinglimit = $10,000 Any opinions? Hal >