Re: [ogpx] Protocol for permitting policy decisions

David W Levine <dwl@us.ibm.com> Tue, 06 October 2009 13:47 UTC

Return-Path: <dwl@us.ibm.com>
X-Original-To: ogpx@core3.amsl.com
Delivered-To: ogpx@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id B21403A69BC; Tue, 6 Oct 2009 06:47:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.829
X-Spam-Level:
X-Spam-Status: No, score=-5.829 tagged_above=-999 required=5 tests=[AWL=0.769, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OLkcY0LzMoPu; Tue, 6 Oct 2009 06:47:43 -0700 (PDT)
Received: from e8.ny.us.ibm.com (e8.ny.us.ibm.com [32.97.182.138]) by core3.amsl.com (Postfix) with ESMTP id 97BCC3A693F; Tue, 6 Oct 2009 06:47:43 -0700 (PDT)
Received: from d01relay02.pok.ibm.com (d01relay02.pok.ibm.com [9.56.227.234]) by e8.ny.us.ibm.com (8.14.3/8.13.1) with ESMTP id n96Dkisu000562; Tue, 6 Oct 2009 09:46:44 -0400
Received: from d01av04.pok.ibm.com (d01av04.pok.ibm.com [9.56.224.64]) by d01relay02.pok.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id n96DnKAu243690; Tue, 6 Oct 2009 09:49:20 -0400
Received: from d01av04.pok.ibm.com (loopback [127.0.0.1]) by d01av04.pok.ibm.com (8.12.11.20060308/8.13.3) with ESMTP id n96DnKuu028450; Tue, 6 Oct 2009 09:49:20 -0400
Received: from d01ml605.pok.ibm.com (d01ml605.pok.ibm.com [9.56.227.91]) by d01av04.pok.ibm.com (8.12.11.20060308/8.12.11) with ESMTP id n96DnK4P028444; Tue, 6 Oct 2009 09:49:20 -0400
In-Reply-To: <3a880e2c0910051638p393b20d1vc12763b59ae17e00@mail.gmail.com>
References: <983F17705339E24699AA251B458249B50CC48CAEBF@EXCHANGE2K7.office.nic.se> <3a880e2c0910051239t3dcae895x4f6d5f4bf5d64cd@mail.gmail.com> <OFE55CFEA3.6AD0DA74-ON85257646.006FC774-85257646.0070F176@us.ibm.com> <3a880e2c0910051638p393b20d1vc12763b59ae17e00@mail.gmail.com>
To: Infinity Linden <infinity@lindenlab.com>
MIME-Version: 1.0
X-KeepSent: 846C2637:4E109B09-85257647:004B1EFF; type=4; name=$KeepSent
X-Mailer: Lotus Notes Release 8.0.2 HF623 January 16, 2009
Message-ID: <OF846C2637.4E109B09-ON85257647.004B1EFF-85257647.004BED84@us.ibm.com>
From: David W Levine <dwl@us.ibm.com>
Date: Tue, 6 Oct 2009 09:49:19 -0400
X-MIMETrack: Serialize by Router on D01ML605/01/M/IBM(Build V851_08302009|August 30, 2009) at 10/06/2009 09:49:19, Serialize complete at 10/06/2009 09:49:19
Content-Type: multipart/alternative; boundary="=_alternative 004BED8485257647_="
Cc: ogpx-bounces@ietf.org, "ogpx@ietf.org" <ogpx@ietf.org>, Magnus Zeisig <magnus.zeisig@iis.se>
Subject: Re: [ogpx] Protocol for permitting policy decisions
X-BeenThere: ogpx@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Virtual Worlds and the Open Grid Protocol <ogpx.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ogpx>, <mailto:ogpx-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ogpx>
List-Post: <mailto:ogpx@ietf.org>
List-Help: <mailto:ogpx-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ogpx>, <mailto:ogpx-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Oct 2009 13:47:47 -0000

Well, I'd again (like the sadly broken record I'm becoming on this topic) 
say its a service or set of services which denies the access, but quite. A 
deployer is free to apply any policy they chose to a service request. If 
they only want people who have visited Candy Mountain, Surrendered a 
Kidney, and can prove it in the form of the ability to respond to provide 
a special token from the magical unicorn powered talisman they get from 
the Leoplueridon to access a given service, so be it. The protocol need 
merely allow them to insert:
<map>
<key>unicorn_talisman_token</key>
<string>shun the unbeliever</string>
</map> 

in an expected spot, and they can reject people who can't provide the 
correct response.

- David
~ Zha






Infinity Linden <infinity@lindenlab.com> 
10/05/2009 07:38 PM

To
David W Levine/Watson/IBM@IBMUS
cc
Magnus Zeisig <magnus.zeisig@iis.se>se>, "ogpx@ietf.org" <ogpx@ietf.org>rg>, 
ogpx-bounces@ietf.org
Subject
Re: [ogpx] Protocol for permitting policy decisions






On Mon, Oct 5, 2009 at 1:33 PM, David W Levine <dwl@us.ibm.com> wrote:

"In order to have rights beyond "guest" on this region, you, or your agent 
domain, on your behalf, needs to have signed the TOS document. I will 
demand a digitally signed proof of this, as metadata when you 
request acess to my region." 

- David 
~ Zha 


i think i grok what you're trying to say here, but i would also add... "a 
given agent domain MAY choose to deny you ANY service (including anonymous 
or guest access) if you don't provide some form of authenticator and 
assert that you have read and understand the domains terms of use."

-cheers
-meadhbh