[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Technical Errata Reported] RFC5176 (2012)



I fail to see a distinction here - but it could be me...

On 26-01-2010, at 23:21 , David B. Nelson wrote:

> It is a semantics issue.   The RADIUS model is to provision services  
> (authorize access) based on authenticated identity, contextual hints  
> from the NAS and server-based policy.  

Correct.  No problem here.

>  The NAS cannot ask questions  
> of the form "Would you allow this user to access that service?"  

This user = authenticated identity. (I have this user)
That service = contextual hints. (port/protocol)

> The  
> NAS can ask questions of the form "I have this user, who has made a  
> connection attempt via that port / protocol, what access should I  
> provision to the user?"

I am sorry i just dont see a difference.




--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>