OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Extended Indeterminate values in the case of Policy Targetsreturning Indeterminate


Hi all

 

I have a question about the extended Indeterminate values in the case that the Target of a Policy or PolicySet matches to Indeterminate.

I can’t find any definition about this case in the specification.

 

Can you please tell me which one of the following solutions is correct?

-          All rules appended to the Policy or PolicySet must be checked. If all of them have the effect Permit, the indeterminate value is Indeterminate(P). If all of them have the effect Deny, the value is Indeterminate(P). Otherwise the value is Indeterminate(DP)

-          It can be assumed that always a rule with a deny effect and a permit effect is appended and therefore Indeterminate(DP) is returned

-          All appended Policies must be evaluated. If all of them are Indeterminate(P) or a Permit, Indeterminate(P) is returned. If all of them have the effect Deny or Indeterminate(D) Indeterminate(D) is returned. If at least one is Deny or Indeterminate(D) and another one is Permit or Indeterminate(P) Indeterminate(DP) is returned.

-          Indeterminate with no value should be returned

 

If it is the case that an Indeterminate is returned I can’t see a definition how this is combined in the Permit-overrides and Deny-overrides algorithms.

 

Can anybody help me in this case?

 

Regards,

 

Stefan

 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]