IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Publickey subsystem draft posted



On Wed, Jul 23, 2003 at 06:35:06PM -0400, Bill Sommerfeld wrote:
> > Also, the restrictions actually stored need not match the restrictions
> > listed in the add request.  This could allow sysadmins to force
> > restriction templates.
> 
> [wg chair hat off]
> 
> I'd hope that the set of restrictions stored would be spec'ed to be a
> superset of the restrictions requested.  

> looking at it another way, the set of things permitted to be done with
> a key would be a subset of the things that the add request requested
> to be permitted...

Yes.

Nico
-- 



Home | Main Index | Thread Index | Old Index