[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] URI-match function proposal
Anne/Bill - I had in mind that uri-subtree-match would be specified in v2. It would use regex (at least) for the local path part. Bill and I may write an RDBMS profile which would layout any necessary restrictions on XACML (including the uri-subtree-match expression) to enable policies to be stored, distributed, located and retrieved by means of RDBMS. This involves computing SQL queries from target match expressions. Hopefully, ipAddress and dnsName matches would be specified in v2. However, we do have to resolve issues concerning ipAddress (e.g. separate functions for v4 and v6 and treatment of default ports). All the best. Tim. -----Original Message----- From: Anne Anderson [mailto:Anne.Anderson@Sun.COM] Sent: Thursday, July 15, 2004 10:55 AM To: Bill Parducci Cc: 'xacml' Subject: Re: [xacml] URI-match function proposal We have discussed moving ipAddress and dnsName match into a separate Profile. Or will uri-match supersede those? Anyway, can we assume they will all be handled in this new Profile, in whatever form they end up? Anne On 15 July, Bill Parducci writes: Re: [xacml] URI-match function proposal > From: Bill Parducci <firstname.lastname@example.org> > To: 'xacml' <email@example.com> > Subject: Re: [xacml] URI-match function proposal > Date: Thu, 15 Jul 2004 07:44:24 -0700 > > ...i think you left out the profile on writing Profiles ;) > > my thinking was that tim and i would take on the Profile for > string-matching-for-fun-and-profit. perhaps not before v2 gets out the > door, but that it is on our plate (aka "the 'people's' plate"? :o) > > b > > Anne Anderson wrote: > > People should be aware that any new profile, if you expect me to > > write it, will have to get in line behind: > > > > - RBAC > > - Hierarchical Resources > > - Multiple Resources > > - SAML > > - DSIG > > - Privacy > > To unsubscribe from this mailing list (and be removed from the roster of the OASIS TC), go to http://www.oasis-open.org/apps/org/workgroup/xacml/members/leave_workgroup.p hp. > -- Anne H. Anderson Email: Anne.Anderson@Sun.COM Sun Microsystems Laboratories 1 Network Drive,UBUR02-311 Tel: 781/442-0928 Burlington, MA 01803-0902 USA Fax: 781/442-1692 To unsubscribe from this mailing list (and be removed from the roster of the OASIS TC), go to http://www.oasis-open.org/apps/org/workgroup/xacml/members/leave_workgroup.p hp.