[cap-talk] ACLs: why not have them IN ADDITION to capabilities

John Carlson john.carlson3 at sbcglobal.net
Sun Jul 30 18:38:21 EDT 2006


On Jul 30, 2006, at 3:23 PM, John Carlson wrote:

> For example, one could use as part of a web key some reference
> to the client side certificate (perhaps stored on the server
> when the capability was granted).
>
> John

If the client side certificate is not available, then the system would
return to the default capability model.

John


More information about the cap-talk mailing list