OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xacml] Proposal to address issue 11, and thoughts on whether it is advisable or not to separate out sections of hier, mult to a new profile


 

> -----Original Message-----
> From: Erik Rissanen [mailto:erik@axiomatics.com] 
> Sent: Wednesday, October 14, 2009 12:36
> To: Rich.Levinson
> Cc: xacml
> Subject: Re: [xacml] Proposal to address issue 11, and 
> thoughts on whether it is advisable or not to separate out 
> sections of hier, mult to a new profile
> 
> 
> Personally I find it difficult to work with expressions like 
> this since it is about performing "matching on a matching 
> language" in order to get the actual resource.

+1
 
> I understand that it may be desirable in some cases to hide 
> the XML content, but that could perhaps be handled better by 
> a construct like this:
> 
> <Request>
>   <Attributes Category="resource">
>     ...
>     <ContentReference .....something here..../>
>   </Attributes>
> </Request>

ContentReference, with an href attribute or content type anyURI, is an
excellent proposal on its own, and should be pursued outside of this
issue.

Another option for hiding content is to encrypt and sign the content (or
entire request) in the transport layer.

--Paul


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]