Schema Central > XACML 2.0 > access_control-xacml-2.0-policy-schema-os.xsd > xacml:Policy
Advanced search
Need SOA Help?

Recommended Reading:

Web Service Contract Design and Versioning for SOA

 

Definitive XML Schema

 

xacml:Policy

Element information

Content

Attributes

NameOccTypeDescriptionNotes
PolicyId [1..1]xsd:anyURI
Version [0..1]xacml:VersionTypeDefault value is "1.0".
RuleCombiningAlgId [1..1]xsd:anyURI

Used in

Sample instance

<Policy        xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os http://docs.oasis-open.org/xacml/access_control-xacml-2.0-policy-schema-os.xsd"
        PolicyId="urn:oasis:names:tc:example:SimplePolicy1"
        RuleCombiningAlgId="identifier:rule-combining-algorithm:deny-overrides">
   <Description>
  Med Example Corp access control policy
 </Description>
   <Target/>
   <Rule RuleId="urn:oasis:names:tc:xacml:2.0:example:SimpleRule1" Effect="Permit">
      <Description>
   Any subject with an e-mail name in the med.example.com domain
   can perform any action on any resource.
  		</Description>
      <Target>
         <Subjects>
            <Subject>
               <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:rfc822Name-match">
                  <AttributeValue DataType="urn:oasis:names:tc:xacml:1.0:data-type:rfc822Name">
       med.example.com
      						</AttributeValue>
                  <SubjectAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                              DataType="urn:oasis:names:tc:xacml:1.0:data-type:rfc822Name"/>
               </SubjectMatch>
            </Subject>
         </Subjects>
      </Target>
   </Rule>
</Policy>

Site developed and hosted by Datypic, Inc.

Please report errors or comments about this site to pwalmsley@datypic.com