xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
RE: [xacml] Modeling Delegation of Rights in a simplified XACML w ith Haskell
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Modeling Delegation of Rights in a simplified XACML w ith Haskell
- From: Tim Moses <[email protected]>
- To: "'Frank Siebenlist'" <[email protected]>, Tim Moses <[email protected]>
- Date: Tue, 25 Nov 2003 11:20:26 -0500
Frank - Yes. Clarified. But, I was expecting that your solution would also solve the "pilot" use-case. It doesn't, does it? All the best. Tim. P.S. For those who aren't familiar with Frank's "pilot" use-case, it allows the issuer of a policy not to possess the privilege that it delegates. P.P.S. What if the delegator and the delegate are both permitted access under disjoint rules? Example: PDP permits access by people in the West of the US. Frank, who lives on the West Coast of the US and therefore has access, grants access to people who live in the East of Canada. Tim lives in the East of Canada. Both Tim and Frank are granted access, but only Frank satisfies the PDP's requirements. Is this what we want?
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]