x500NameIsIn Function Description

Description

Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type x500Name are compared using the x500NameEqual function.

x500NameIsIn belongs to the ALFA function reference's Bag functions category. It maps to the XACML function identifier urn:oasis:names:tc:xacml:1.0:function:x500Name-is-in, takes 2 arguments and returns a value of type boolean.

Property Value
Category Bag functions
# Arguments 2
Arguments
  • atomic (single) value of type x500Name
  • bag (collection) of values of type x500Name
Return Value boolean
Expressed As pre-fix
Representation ALFA short name
Allowed In Target true
ALFA Shorthand None
Commutative false

Example

/**
* Allow if Steve Kille is in the list of retrieved RDN values
*/
rule x500NameIsInExample{
    permit
    condition x500NameIsIn("CN=Steve Kille,O=Isode Limited,C=GB":x500Name,rdn)
}

Permit if the value passed as the first parameter is in the bag of values passed as the second parameter