RE: [xacml] XACML TC position on SAML Attribute meta-data

From
Anne Anderson <>
Date
2004-04-07T18:35:00+00:00
ID
Thread
RE: [xacml] XACML TC position on SAML Attribute meta-data
MHonArc v2.5.0b2 -->

xacml message

[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]

Subject: RE: [xacml] XACML TC position on SAML Attribute meta-data

From: Anne Anderson <>

To: Daniel Engovatov <>

Date: Wed, 07 Apr 2004 14:50:53 -0400

Daniel,

I suggest we separate the issue of support for concatenating name
components in general from the issue of support for a specific
"scope/namespace/source" name component.

So long as a deterministic concatenation order is specified, it
should be possible to omit any name component from a
concatenation if desired.

Anne

On 7 April, Daniel Engovatov writes: RE: [xacml] XACML TC position on SAML Attribute meta-data
 > From: Daniel Engovatov <>
 > To: , XACML TC <>
 > Subject: RE: [xacml] XACML TC position on SAML Attribute meta-data
 > Date: Wed, 07 Apr 2004 11:01:05 -0700
 > 
 > 
 > In regard to N.4:  I think we should seriously consider adding
 > "scope"/"namespace"/"source" as a separate attribute, not part of the
 > attribute name.
 > That will allow for much more flexibility and interoperability in
 > expressing context view of enterprise data: it typically has myriad of
 > sources not easily grouped into our 4 predefined scopes (<subject>,
 > <resource>, <action>, <environment>).  Concatenation and other form of
 > name mangling is usually a very non-robust way for name conflict
 > resolution.
 > 
 > This separated attributes may be made part of existing "scopes", or the
 > concept of scope can be made extensible.
 > 
 > So, I would not sign on item 4)  I agree with others.
 > 
 > Daniel.
 > 
 > 
 >