OASIS Open Mailing List Archives  ·  All Lists  ·  xacml  ·  2003-11

xacml — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

RE: [xacml] Modeling Delegation of Rights in a simplified XACML with Haskell


 MHonArc v2.5.0b2 -->
















xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xacml] Modeling Delegation of Rights in a simplified XACML with Haskell


Frank - Let me see if I've got this right ...

1. An XACML policy has an identified issuer.
2. Whether or not a subject is permitted to issue a policy can be stated as
an XACML policy (I'll call this an intermediate policy), which (in turn) has
an identified issuer.  The issuer of a policy is treated as the subject in
its immediate "upstream" policy.  So a chain is formed.  Valid chains
terminate with the PDP.
3. The subject of an intermediate policy can be identified by name or by any
other attribute.
4. The immediate downstream policy in a chain can be identified by name or
by its contents using our ResourceAttributeDesignator and
ResourceAttributeSelector mechanisms.
5. A combining algorithm will specify how the decisions from each of the
policies in a chain are to be combined to produce the ultimate access
decision.

Obviously, there are other subtleties.  But, I wanted to be sure I had this
coarse level correct before delving further.

Is an action specified in an intermediate policy?

What about delegated attributes?  Is this outside the scope of your
proposal?  Don't we need to solve this, too?

All the best.  Tim.




[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]