OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xacml-dev message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Base and Permit-biased PEPs


I have a question about section 7.1.1 and 7.1.3, the Base PEP and
the Permit-biased PEP in 2.0. Those sections say that "If the decision is 
"Deny", then the PEP SHALL deny access.  If obligations accompany the 
decision, then the PEP shall deny access only if it understands, and it 
can and will discharge those obligations."

Suppose the decision is "deny" with obligations and the PEP cannot 
understand or discharge the obligation, does this result in a "permit"? 
The above sentance says the PEP will only deny if it understands and 
can do the obligation, so what happens when it can't understand or 
discharge the obligation?

Mary Kolencik



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]