xacml message

Subject: RE: [xacml] apr15 schema subcom issues

Hi all,

Thanks to Anne for pointing to these sources. BTW, I checked XACML
document repository and found 6 references to Ponder project. Did
anybody have a chance to get familiar with what specifically those
people have done? What I got out of brief scanning the paper Anne
reffered to, they used OCL for specifying constraints in their policies
as well as expressions in Ponder's "meta-policies." The Ponder project
must have quite a bit of experience with using OCL in the access control
problem domain.

This discussion of using a language for combiners made me think of
something else (but not completely different). If it is really a goal
for XACML TC to produce such a spec that any two XACML-compliant PDPs
would always return the same result for any given authorization request
and policy, then the spec needs to be very precise not only about the
semantics of standard combiners. It needs to have precise definition of
semantics for many other things in the schema. By "precise definition" I
mean here a definition in some formal language and not in plain English.
If this TC defines precisely the semantics of only standard combiners,
the TC would not achieve this goal. If so, then the TC could just
acknowledge this fact by explicitly saying somewhere in the spec that
the spec is not giving precise definition of the semantics for the
schema elements, and move on without spending the members' time on
"covering" combiners. This decision could be re-evaluated in later
versions of the spec though when all bigger problems are solved.

Best regards

On 17 April, ernesto damiani writes: [xacml] apr15 schema subcom issues
 > One more comment about OCL: it has been used with mixed results as a
 > language for class declaration repositories, e.g. to select existing
 > declaration and implementations that "match" a given template.
 > As a language for describing algorithms from scratch well... it has
 > drawbacks.

OCL was used in the following two access control policy
projects, but I had trouble understanding the resulting

