Sounds reasonable. Keep the rules/policies as passive documents and attribute action to the PDP.
Danny Thorpe
Authorization Architect
Dell
| Identity & Access Management, Quest Software
Quest Software is now part of Dell.
From: [mailto:]
On Behalf Of Tolbert, John W
Sent: Tuesday, August 06, 2013 10:48 AM
To:
Subject: [xacml] Target definition
On the last call, I said that it was too soon to start working on 4.0. I am holding to that, but have a suggested change for the definition for “target” when the time is right.
3.0--
Target
The set of decision requests, identified by definitions for
resource, subject and action that a
rule, policy, or policy set is intended to evaluate
Proposed--
Target
The set of decision requests, identified by definitions for
resource, subject and action that a
PDP is intended to evaluate according to the applicable rule,
policy, or policy set
Thoughts?