On 8/27/07, David Boyes <[EMAIL PROTECTED]> wrote:

> So you're proposing a *AUTH or something like that where you can pose a
> authorization question from a user, which will be answered by whatever
> is connected to *RPI?

The need to do an IUCV connection adds a lot of complexity we don't
need. I think that if we want even locally written tools to exploit
this, a CP command would be better. Even if that means it becomes a
synchronous interface. So
  CP CANYOUDO <resource name> <access mode>

> IUCV has the advantage that it can already be transported across ISFC,
> which would allow concentrating authorization information on certain
> nodes in a cluster, a useful scalability and auditability feature.

I think it would be enough to get CP's answer on *this* system,
whatever way CP has come to that conclusion. If CP would trust to
connect to the ESM via ISFC, then CP may use that...

Rob

Reply via email to