Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6B8808@G4W3222.americas.hpqcorp.net> |
Rob Meijer wrote: > > When I go to the gym, their locker system provides me with a locker number, > I can than create my own authorization token (pin) and can than store my stuff > in that locker, ones I'm done I can use the authority implied by the > locker-number + pin to again gain access to the locker. No identity, > no authentication presupposed or otherwise. > My gym has the same kind of lockers. Clearly, you can lock your stuff in any unused locker, whether it was assigned to you or not. What's really happening is that you are authenticated when you enter the gym and given the authorization to use any unused locker with the understanding that you will use the one assigned to you. That's something I didn't mention in my description of access control, policy. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp