next up previous contents
Next: 4.3.9 How would access Up: 4.3 Administrator Previous: 4.3.7 How do servers

4.3.8 ../images/greenball.gifWhat about transient objects created by factories?

 
change_begin

[ed. For more detailed and alternative answers see SecSIG mail list discussion thread titled ``Granularity of Invocation Access Controls'']

Bob Blakley
(June, 1999)26:
The idea here is that factory objects should conform to the administered creation-time policy which determines what domain(s) an object should be assigned to. This is really independent of whether or not the objects are transient or persistent, and of whether they are named or anonymous.

change_end