blob: 644cf1e049395290003906c6c340bd728166f2db [file] [log] [blame]
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<Policy xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" PolicyId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIC085:policy" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides" Version="1.0" xsi:schemaLocation="urn:oasis:names:tc:xacml:3.0:policy:schema:os access_control-xacml-2.0-policy-schema-os.xsd">
<Description>
Policy for Conformance Test IIC085.
</Description>
<Target/>
<Rule Effect="Permit" RuleId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIC085:rule">
<Description>
Julius Hibbert can perform any action on any resource.
</Description>
<Condition>
<Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:x500Name-match">
<AttributeValue DataType="urn:oasis:names:tc:xacml:1.0:data-type:x500Name">cn=Julius Hibbert,ou=Springfield Office, o=Medico Corp, c=US</AttributeValue>
<Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:x500Name-one-and-only">
<AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" DataType="urn:oasis:names:tc:xacml:1.0:data-type:x500Name" MustBePresent="false"/>
</Apply>
</Apply>
</Condition>
</Rule>
</Policy>