Re: Ideas from the I&A Forum (DCE file permissions)

At 11:52 AM 7/10/96 -0400, Rich Salz wrote:
>> I still don't know what the DCE "T: test" permission is
>> good for, so I can't suggest we add it.  Rich?
>The "T (test)" permission is useful when --
>    -	You only want to grant someone "read ACL" rights, and not "read object"
>	rights.  As in "ls -l" vs. "cat"

Is this different from giving read permission on the directory file but not
on the files in that directory?

>    -	You want to allow a comparison without disclosing the full state,
>	such as "Can Rich read this file" or "Is Rich in the 'foo' group?"
>	As in "grep ... >/dev/null ; echo $status" vs. "cat"

In the hypothetical file system protected by SPKI certs, I believe this
concern translates to the ability to read certs themselves.  Am I
understanding you?

That's something we just didn't address.

>Hope this helps.  Nice seeing you again Carl.

Yup -- it helps.  Nice seeing you again, too..

 - Carl

