[cap-talk] Concening entry "ambient authority" in Wikipedia

Matej Kosik kosik at fiit.stuba.sk
Sat Jun 6 02:23:38 EDT 2009


Mark Miller wrote:
> I would define an ambient authority system as one in which "If a
> requesting entity requests an action that it is permitted to perform,
> then the action is allowed."

If we take this definition, then would it cover both:
- subsystems with ambient authority
- subsystems with non-ambient authority
  (where we can rely on object-capability security model)
?

In both cases holds that:

  "If a requesting entity requests an action that it is permitted
   to perform, then the action is allowed."

because the phrase

  "... an action that is permitted to perform ... "

has different meanings in both cases.


More information about the cap-talk mailing list