OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [xacml] combining algorithm paper



On Jun 29, 2011, at 10:32 AM, rich levinson wrote:

> However, if the policy is ordered-X-overrides, then things are deterministic.

Thanks Rich, 

The problem is that there is no context for serialization in a mixed environment. Multiple Obligation "namespaces" cannot be resolved. Consider two Obligation Families that must be combined in an ordered fashion:

Obligation Family 1:
X < Y < Z

Obligation Family 2:
A < Z < Y

If Z & Y are returned whch is enforced?

I offer that there much be something with awareness that spans PolicySets (and therefore federated systems) that can address this. 

b



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]