Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6B8194@G4W3222.americas.hpqcorp.net> |
I have some stuff on slides I used for an RSA talk that talks about access control having four steps. 1. Identification - knowing who to throw in jail. Well, OK, just knowing who to hold responsible. It's what we do when setting up an account for a new user. 2. Authentication - what a process must do to be able to use the privileges assigned to an identified individual 3. Authorization - granting a right to be associated with a particular authentication, e.g., adding an entry in an ACL 4. Access decision - deciding whether or not to honor a request By the way, the statement about authentication is imprecise in a significant way. Authentication only proves that you possess specific credentials. It only specifies who you are (identification) if those credentials were not shared either intentionally or unintentionally. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp