OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: RE: XACML TC Charter Revision - Strawman


Hal is on the right track here with what I imagined XACML to be used for
i.e. provision a PDP. 

As to what the PDP actually does with the XACML, i.e. return just yes/no
decisions, return policy fragments, return entire policies, or return sets
of policies, I had imagined that such functionality would be determined by
the implementer of the PDP based on the desired behavior. In fact a PDP is
but one possible interface to a policy repository. The policy repository may
well need a provisioning/administrative interface that makes no policy
decisions. 

At Psoom we have a specific need that is not strictly security enforcement
related that requires the exposure of policy detail. As Bill Parducci has
pointed out, the exposure of policy could allow for the circumvention of
policy, this is bad in a strict security sense. On the other hand, the
exposure of policy can allow for the adjustment of behavior such that it is
compliant with policy, which is good from an operational perspective, e.g.
unless you tell me policy requires that I have a $5,000 balance in my bank
account to access certain services, how can I possible comply with the
policy?

Ernesto, Michiharu, and Ken Y. - jump in here, I think you guys have done
the most work so far in actually representing policy as XACML as wells as
issuing decisions based on the policy.

>