Hi there,
I am still a novice and trying to grasp the concepts of XACML. applogies for
any silly questions..i would appreciate any suggestions related to adding
multiple resource attributes and corresponding action in a policy rule..
Scenario..
Role --- student (has permissions on three resources and different
permissions)
1)
Permission --- read
on
Resources --- course-info and exam-results..
2)
Permission --- write
on
Resources --- personal-data
How will i create a permission policy set for this type of scenario....while
going through xacml profile for RBAC i found " permission <policy set>
associated with a given role may allow acces to multiple resources using
multiple actions ..
Could any body help me with this,how will i proceed ... any suggestions will
be appreciated ..
Regards
Nafees