Next in thread →
Next in month →
Re: A Problem with the "delegated:" Prefix
If a change to the XML Schema is entertained, then it would be easier all round to just get rid of the category prefixing altogether and instead label each policy as either an access policy or an administrative policy. When assessing an access request the PDP would ignore any policy labelled as an administrative policy. When assessing an administrative request the PDP would ignore any policy that is *not* labelled as an administrative policy. The procedure for generating an administrative request would be much the same as it currently is except that steps 1.b. and 1.d. are replaced with "An <Attributes> element with any other Category maps to an identical <Attributes> element". Labelling the policies solves a number of problems. The problem that prefixing an arbitrary category URI does not necessarily result in a valid URI goes away. The need to prefix XPathCategory values goes away. The problem of what to do with access requests that contain categories that are already prefixed goes away. Also, the implementation of delegation becomes easier for PDPs, PAPs and policy writers, and allows more efficient processing by PDPs. Regards, Steven On 24/05/2012 10:00 AM, Steven Legg wrote:
Next in thread →
Next in month →