IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: Publickey subsystem draft posted
On Wed, Jul 23, 2003 at 06:35:06PM -0400, Bill Sommerfeld wrote:
> > Also, the restrictions actually stored need not match the restrictions
> > listed in the add request. This could allow sysadmins to force
> > restriction templates.
>
> [wg chair hat off]
>
> I'd hope that the set of restrictions stored would be spec'ed to be a
> superset of the restrictions requested.
> looking at it another way, the set of things permitted to be done with
> a key would be a subset of the things that the add request requested
> to be permitted...
Yes.
Nico
--
Home |
Main Index |
Thread Index |
Old Index