[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Subject: RE: XACML TC Charter Revision - Strawman
Hal is on the right track here with what I imagined XACML to be used for i.e. provision a PDP. As to what the PDP actually does with the XACML, i.e. return just yes/no decisions, return policy fragments, return entire policies, or return sets of policies, I had imagined that such functionality would be determined by the implementer of the PDP based on the desired behavior. In fact a PDP is but one possible interface to a policy repository. The policy repository may well need a provisioning/administrative interface that makes no policy decisions. At Psoom we have a specific need that is not strictly security enforcement related that requires the exposure of policy detail. As Bill Parducci has pointed out, the exposure of policy could allow for the circumvention of policy, this is bad in a strict security sense. On the other hand, the exposure of policy can allow for the adjustment of behavior such that it is compliant with policy, which is good from an operational perspective, e.g. unless you tell me policy requires that I have a $5,000 balance in my bank account to access certain services, how can I possible comply with the policy? Ernesto, Michiharu, and Ken Y. - jump in here, I think you guys have done the most work so far in actually representing policy as XACML as wells as issuing decisions based on the policy. >