[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Technical Errata Reported] RFC5176 (2012)
I fail to see a distinction here - but it could be me...
On 26-01-2010, at 23:21 , David B. Nelson wrote:
> It is a semantics issue. The RADIUS model is to provision services
> (authorize access) based on authenticated identity, contextual hints
> from the NAS and server-based policy.
Correct. No problem here.
> The NAS cannot ask questions
> of the form "Would you allow this user to access that service?"
This user = authenticated identity. (I have this user)
That service = contextual hints. (port/protocol)
> The
> NAS can ask questions of the form "I have this user, who has made a
> connection attempt via that port / protocol, what access should I
> provision to the user?"
I am sorry i just dont see a difference.
--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>