xacml message

Subject: [xacml] Questions about Context

Colleagues - I have the following questions about Context.

1. Should we repeat Subject and Actions in the Response?  If there are multiple Subjects and Actions in the Request, will it always be clear which Subject was permitted which Action?

2. Should we call "Other" "Environment"?  The term "Other" doesn't convey much information to the reader.

3. What is the purpose of the Qualifier attribute in the SubjectIdType definition?

4. In Policy.xsd we use the term "Designator" (policy, rule, attribute).  In Context.xsd we use the term "ResourceSpecifier".  Is this inconsistent?

5. In ResourceSpecifier the ResourceId is of type xs:anyURI.  Should this not be xs:string?  Otherwise, non-xml resource instances cannot be named.

6. The Scope element is in both the Request and the Response.  Do we need it in the Response?  Will one ever want to say the Request is permitted for children, but not for descendants, etc.?

Do we need a discussion to answer these questions?  All the best.  Tim.

Tim Moses
Tel: 613.270.3183

