Comments on SPKI draft of 25 March 1997

On Question 5:

I am in favor of making the may-delegate field boolean (that is,
0/1 valued), as I can't see why someone might need more.  Certainly,
the security implications between  ( may-delegate 1 ) and ( may-delegate 2 )
are hardly crisp, since you are depending on your delegee to determine
who gets delegated to in either case (either directly by his own judgement,
or indirectly via his delegees).  

Ron Rivest