Skip to Content.
Sympa Menu

mace-opensaml-users - SubjectAttributeDesignator question

Subject: OpenSAML user discussion

List archive

SubjectAttributeDesignator question


Chronological Thread 
  • From: "Lanz, Dan" <>
  • To: "OpenSAML" <>
  • Subject: SubjectAttributeDesignator question
  • Date: Tue, 24 Jan 2006 16:00:31 -0500

How does one programmatically access the xml attributes of the SubjectAttributeDesignator element?  The SubjectAttributeDesignator is a subelement of the SubjectMatch element in an xacml policy target, as shown in the policy fragment below:
 
  <Target>
    <Subjects>
      <Subject>
        <SubjectMatch
            MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue
            DataType=http://www.w3.org/2001/XMLSchema#string
              >employee</AttributeValue>
          <SubjectAttributeDesignator
            AttributeId="group"
            DataType="http://www.w3.org/2001/XMLSchema#string"/>
        </SubjectMatch>
      </Subject>
      ...
   </Target>
 
The subject attribute value is available from an EvaluationCtx by calling (as an example):
  getSubjectAttribute(new URI(com.sun.xacml.attr.X500NameAttribute.identifier), new URI("urn:oasis:names:tc:xacml:1.0:subject:subject-id"),
    new URI("urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"))
 
But, it's not evident how to access the SubjectAttributeDesignator.
 
Thanks,
Dan Lanz
 



Archive powered by MHonArc 2.6.16.

Top of Page