[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: grant / deny precedence indraft-ietf-ldapext-acl-model-04.txt

> David (and others),
> Here's the question:  Do we want to include subjects other
> than access-id, role, and group?
> Ellen

Like Jim, I do not recognise a difference from the access control 
perspective between the currently defined role and group. Therefore 
I would suggest delete role.
I do also suggest that subtree is added, as this is clearly different to 
group (and role).



David Chadwick
IS Institute, University of Salford, Salford M5 4WT
Tel +44 161 295 5351  Fax +44 161 745 8169
Mobile +44 790 167 0359
Email D.W.Chadwick@salford.ac.uk
Home Page  http://www.salford.ac.uk/its024/chadwick.htm
Understanding X.500  http://www.salford.ac.uk/its024/X500.htm
X.500/LDAP Seminars http://www.salford.ac.uk/its024/seminars.htm
Entrust key validation string MLJ9-DU5T-HV8J
