Re: Avoiding IBAC
"Neal H. Walfield" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <87bnpdfiaw.wl%[email protected]> |
Hi Alan, At Wed, 15 Oct 2014 14:59:30 +0000, Karp, Alan H wrote: > When we talk about capabilities on this list, we're usually > referring to #4. However, deciding to delegate typically uses #2 to > influence #3. In your scenario, I think it would be easier to > assign roles to people and label the files, but you can use ACLs. > The key point is that you are using the roles or ACLs to make > authorization decisions, not access decisions. You seem to distinguish labeling files from ACLs. But if the label is connected to the object, how is it different from an ACL (the authorization "arrow" is pointing from the object to the subject rather than from the cap to the object). Neal