xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Re: Minor XACML Spec errata and resource labels
Dear Jeff,
Thank you for the erratum. I have forwarded it to the
xacml-comment mailing list.
I assume, by "resource label", you mean a classification scheme
and a classification value, such as "U.S. Navy Classification
System XYZ" "top secret". This could be expressed in XACML as an
"Attribute" of the Resource. The AttributeId could be a URN
indicating the classification scheme, and the AttributeValue
could be the classification value.
Does this satisfy your requirements?
Anne Anderson
On 19 April, Jeff writes: Minor XACML Spec errata and resource labels
>
From: "Jeff" <[email protected]>
>
To: <[email protected]>
>
Subject: Minor XACML Spec errata and resource labels
>
Date: Sat, 19 Apr 2003 17:02:54 -0400
>
> Hi Anne,
>
> Thanks for all the great XACML work :-)
>
> There's a minor error on line 1674 (page 44, PolicySet line [071]) of oasis-####-xacml-1.0.pdf: please remove the trailing slash.
>
> I don't see anything in XACML relating to resource labels (in fact the word label doesn't appear at all in oasis-####-xacml-1.0.pdf!). Resource labels are part of the authorization support in the X.509 standard and are used in several RBAC implementations. Resource labels are useful in enabling resource characteristics (i) to be set on resources and (ii) to form part of access control decisions. I feel sure that you must be aware of this and can only conclude that a PolicySet is intended to act as a resource label (in addition to acting as a policy set!). Is this correct?
>
>
> Warmest regards,
>
> Jeff Lawson
> Cogent Logic
> Toronto, Canada
> (416) 340 8025
>
>
>
>
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]