When creating ACLs, it is imperative that the Personae that are used for user identities be created by the exact same User Authority that is being used by the secured repository. The User Authority may not be a proxy even though the Personae produced by a proxy test is equivalent to the Personae produced by the User Authority that it is a proxy for. This is because the identity name spaces used by a User Authority and its proxies may not be the same, and the ACL parser cannot support multiple identity namespaces.

 
loading table of contents...