[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: ietf-provreg@cafax.se
From: Dave Crocker <dcrocker@brandenburg.com>
Date: Mon, 19 Feb 2001 18:05:52 -0800
In-Reply-To: <200102192205.f1JM5oA15676@zed.isi.edu>
Sender: owner-ietf-provreg@cafax.se
Subject: Re: grrp-reqs-06, 11. Security Considerations [3]

 From the message thread, I am getting the sense that something basic is 
being missed.  Indeed it might be that *I* am the one doing the missing, 
but just in case not...

         Policy vs. mechanism...

It is neither complicated nor unusual to have a mechanism that permits 
separate bags of bits to be labeled, according to some SEPARATELY defined 
policy.

Defining such policies can be quite difficult, but why don't we separate 
that task from the one of simply permitting data "sections", with each 
section having its own label and being subject to possibly separate 
handling policies?

d/

----------
Dave Crocker   <mailto:dcrocker@brandenburg.com>
Brandenburg InternetWorking   <http://www.brandenburg.com>
tel: +1.408.246.8253;   fax: +1.408.273.6464


Home | Date list | Subject list