Re: Avoiding IBAC
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD5419524B9@G9W0755.americas.hpqcorp.net> |
Neal H. Walfield wrote: > > You seem to distinguish labeling files from ACLs. But if the label is > connected to the object, how is it different from an ACL (the > authorization "arrow" is pointing from the object to the subject > rather than from the cap to the object). > An ACL says what permissions the requesting subject has. What I described works a bit differently. The delegation is allowed or denied based on who the delegatee is, not who is requesting the delegation. Still, you are right that the arrow is pointing from the object to a subject. While that is a problem if the arrow is used to make an access decision, I don't believe it's a problem if it's only used to make a grant decision. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 1 (650) 386-4568 http://www.hpl.hp.com/personal/Alan_Karp