← Prev in month
← Prev in thread
Re: [xacml-comment] Extended Indeterminate values in the case ofPolicy Targets returning Indeterminate
Hi Stefan,
You have raised an interesting question that appears to test some of
the limit cases of the
combining algorithms, which may not be explicitly represented in the
spec, although,
possibly they are implicitly covered when examining the details.
I propose that the following might resolve the issue:
Based on section 7.11 of XACML 3.0, in order for a Policy to
evaluate to Permit or Deny,
at least one Rule must evaluate to its Effect. i.e. if a Policy
contains zero Rules it must evaluate
to NotApplicable or Indeterminate{noValue} (which, for practical
purposes, I think is
equivalent to NotApplicable, since you need an Effect to activate
Obligations or Advice)
Given then that there are Rules of some sort (either in a Policy
or below in some Policy
contained in a PolicySet) following the Target, which was
Indeterminate, those Rules would
need to be "looked at" or "checked" to determine possible Permit or
Deny outcomes that
could have occurred if the Target had been Applicable.
The checking needs to follow the policy and rule combining
algorithms that process the
Indeterminate{P,D,PD}cases explicitly.
Hopefully, this helps.
Thanks,
Rich
wrote:
Hi all
I have a
question about the extended Indeterminate values
in the case that the Target of a Policy or PolicySet matches to
Indeterminate.
I can’t find
any definition about this case in
the specification.
Can you
please tell me which one of the following
solutions is correct?
-
All rules appended to the
Policy or PolicySet must be checked. If all of them have the effect
Permit, the
indeterminate value is Indeterminate(P). If all of them have the effect
Deny,
the value is Indeterminate(P). Otherwise the value is Indeterminate(DP)
-
It can be assumed that
always a rule with a deny effect and a permit effect is appended and
therefore
Indeterminate(DP) is returned
-
All appended Policies
must be evaluated. If all of them are Indeterminate(P) or a Permit,
Indeterminate(P) is returned. If all of them have the effect Deny or
Indeterminate(D) Indeterminate(D) is returned. If at least one is Deny
or
Indeterminate(D) and another one is Permit or Indeterminate(P)
Indeterminate(DP) is returned.
-
Indeterminate with no
value should be returned
If it is the
case that an Indeterminate is returned I
can’t see a definition how this is combined in the Permit-overrides and
Deny-overrides algorithms.
Can
anybody help me in this case?
Regards,
Stefan
← Prev in month
← Prev in thread