HERAS-AF Forum
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 20, 2012, 11:40:45 am

Login with username, password and session length
Search:     Advanced search
Welcome to the HERAS-AF Forum...
373 Posts in 89 Topics by 272 Members
Latest Member: Jasmine
* Home Help Search Login Register
+  HERAS-AF Forum
|-+  HERAS-AF XACML (0.x, "old")
| |-+  HERAS-AF XACML (Moderator: Florian Huonder)
| | |-+  Which policies should be resolvable by the reference loader?
« previous next »
Pages: [1] Print
Author Topic: Which policies should be resolvable by the reference loader?  (Read 927 times)
Florian Huonder
Administrator
Full Member
*****
Posts: 129



View Profile WWW
« on: September 06, 2009, 03:41:11 pm »

I am thinking about the implementation of the reference loader in the evaluation engine.
There are to basic possible solutions and I am not sure which to take, or which is the right one.
The point that I am talking about is the fetching of local policies (e.g. if a "remote" PDP asks for a policy or if the "local" PDP needs to resolve a local policy)
Assuming the following policy-tree locally deployed, see attachment policies.png.

The following two scenarios are thinkable (imho):
  • If a "remote" PDP asks for a policy it is only able to fetch PS1 and PS2 (as a whole, that means including their subpolicies). Example: If a "remote" PDP asks for PS1 it gets a tree with PS1 as a root and two child-elements (P1 and P2)
  • A "remote" PDP is able to fetch every deploy policy. That means it is possible to get PS1 (as a whole) or any of the Policies P1  - P4.

In my opinion the first solution is the one to go for because from my point of view it does not make sense that someone is able to get subpolicies, without "context".

I am very interested in your opinion.

Regards,
Florian


* policies.png (8.02 KB, 501x267 - viewed 55 times.)
Logged
Stefan Oberholzer
Core Member
Newbie
*
Posts: 2


View Profile
« Reply #1 on: September 17, 2009, 01:10:48 pm »

I think it must be the second solution.
A single policy can be used by multiple policy sets. This must also be possible with remote policies. An example is listed in the attached picture.


* PolicyTree.png (20.01 KB, 927x354 - viewed 51 times.)
Logged
Florian Huonder
Administrator
Full Member
*****
Posts: 129



View Profile WWW
« Reply #2 on: September 18, 2009, 08:13:58 am »

Hi Stefan,
When I look at your example I fully agree. We should go for the second solution.

Any other inputs / hints?

Regards
Logged
Pages: [1] Print 
« previous next »
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!