OASIS eXtensible Access Control Markup Language (XACML) TC

 View Only

RE: [xacml] Re: env attributes

  • 1.  RE: [xacml] Re: env attributes

    Posted 10-24-2002 10:09
     MHonArc v2.5.2 -->
    
    
    
    
    
    
    
    
    
    
    
    
    
    
    
    
    
    

    xacml message

    [Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


    Subject: RE: [xacml] Re: env attributes


    On Wed, 23 Oct 2002, Daniel Engovatov wrote:
    
    > ..given request and policy and CONTEXT, which very well may include global
    > parameters independent of an individual request..
    >
    > Also, auditing is best done where the decision is made, not were it is used,
    > as auditing may include information not returned to PEP (such as a reason
    > for DENY)..
    
    Well, "best" is only an opinion which depends upon the application, and
    the auditing that is required for that application. The decision, itself
    could have been made weeks ago. Actually when you write the policy, you've
    have *already* made the decision.
    
    Cheers,
    -Polar
    
    >