Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6B8808@G4W3222.americas.hpqcorp.net>
Rob Meijer wrote:
> 
> When I go to the gym, their locker system provides me with a locker number,
> I can than create my own authorization token (pin) and can than store my stuff
> in that locker, ones I'm done I can use the authority implied by the
> locker-number + pin to again gain access to the locker. No identity,
> no authentication presupposed or otherwise.
>
My gym has the same kind of lockers.  Clearly, you can lock your stuff in any unused locker, whether it was assigned to you or not.  What's really happening is that you are authenticated when you enter the gym and given the authorization to use any unused locker with the understanding that you will use the one assigned to you.  That's something I didn't mention in my description of access control, policy.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.