Limits of SEMA RBAC Conflict Resolution with Expired Credentials
26K reputation · 18 Jan 2025, 17:34 UTC
Context
SEMA’s role‑based access control (RBAC) assigns permissions to roles rather than individual users, aiming to enforce least‑privilege. Credentials can be flagged as expired; when used, SEMA denies access to protected resources. However, the policy language does not specify how to resolve conflicts when a user holds multiple roles that grant overlapping permissions, nor does it automatically remove expired credentials from the session cache.
Unresolved Decision
Given these gaps, the precise behavior of SEMA when a user’s active roles overlap and one or more credentials are expired remains unclear. This ambiguity affects how administrators can design secure, least‑privilege policies and manage session cleanup.
Key Questions
1. When a user has multiple roles with overlapping permissions, how does SEMA prioritize or combine those permissions during policy evaluation?
2. Does SEMA automatically revoke expired credentials from an active session cache, or must administrators manually purge them?
3. Is there a configuration option to exclude permissions granted via expired credentials from the effective permission set?