xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Re: [xacml] Inputs to rfc822Name-match
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [xacml] Inputs to rfc822Name-match
- From: Bill Parducci <[email protected]>
- To: "'XACML'" <[email protected]>
- Date: Thu, 13 May 2004 06:49:57 -0700
perhaps we could create a 'mask' that would the name to conform, but provide for a range of values to match? (ala IP masking) in other words the resource could be '[email protected]' with a mask of '@bar.com' and any request of type rfc822 containing the domain '@bar.com' would result in a match. it is kind of a long way around to do the same thing i think tim is asking for but it leaves the rfc822 names valid and extends by allowing the [soon to be omnipotent ;o] context handler to match a range via an *extension* of the rfc822 names. i dunno, just thinking out of the box. (i definitely think there is a valid use case for this). b Tim Moses wrote: > Seth - I am picturing a situation like this ... > > A policy is written to apply to the resource "email addresses". In this > case, the target would contain a resource match with the attribute > designator "resource-id", of type "string" and value "*". > > A context request is received containing the resource attribute > "resource-id", of type "RFC 822 name" and the value "[email protected]". > > How can the PDP tell that the policy is applicable? The resource-ids match, > the data types don't match and "*" isn't obviously an email address. > > So, always making the general form the same type as the specific form would > assist matching. This happens naturally for X.500 names and (I hope) the > other name forms. > > All the best. Tim. > >
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]