John Merrells,
As in D002, this Condition was intended to produce an
Indeterminate result (by passing the wrong argument type to the
function) in order to test the requirements of the
"first-applicable" algorithm, which says that a Permit or Deny
result will be returned even if an Indeterminate result follows.
Please let me know if I am overlooking something.
Anne Anderson
On 26 November, John Merrells writes: [xacml-comment] D024
> From: John Merrells <>
> To: "''" <>
> Subject: [xacml-comment] D024
> Date: Tue, 26 Nov 2002 17:36:20 -0800
>
>
> Same as D002...
>
> <Condition
> FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
> <SubjectAttributeDesignator
>
> AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
> DataType="http://www.w3.org/2001/XMLSchema#string"/>
> <AttributeValue
>
> DataType="http://www.w3.org/2001/XMLSchema#string">Zaphod
> Beedlebrox</AttributeValue>
> </Condition>
>
>
>
> ----------------------------------------------------------------
> To subscribe or unsubscribe from this elist use the subscription
> manager: <http://lists.oasis-open.org/ob/adm.pl>
>
--
Anne H. Anderson Email:
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311 Tel: 781/442-0928
Burlington, MA 01803-0902 USA Fax: 781/442-1692