Re: auth fields

Carl Ellison wrote:
> Hi Ron.
> At 11:10 AM 3/11/97 EST, Ron Rivest wrote:
> >You mentioned a "sorting order" for auth fields.  This implies that
> >you want what mathematicians call a "total order" on the elements, so that
> >between any two such elements you have a relationship (either greater,
> >less than or equal to).
> No, I had always been thinking of a partial order -- maybe a lattice --
> although it's not clear that any such lattice would be closed.
> E.g., in your filesystem example, 
> "ftp://cybercash.com/pub/cme/"
> and
> "ftp://theory.lcs.mit.edu/pub/rivest/"
> might theoretically be both subordinate to 
> "ftp:"
> but there might be no cert ever generated for that lattice point.
> The problem with thinking of such lattices, to me, is that for some real 
> uses of certs, we'll need to be able to do an occasional PolicyMaker 
> translation of <auth> -- something that I don't know how to express in such 
> a form.  A PolicyMaker program would join arbitrary places on such a
> lattice.

You want to be a bit careful about terminology here, because "join" and "meet"
are the defined operations on a lattice, if I remember things correctly. I
suspect that you didn't mean "join" in the lattice sense (and please don't ask
me to define that ... but I know a man who can ;-). Correct me if I'm wrong!



> Agree?
>  - Carl
