On Wed, 2008-08-27 at 16:21 -0700, David Powell wrote: > Not only *can* you delegate the ability to administer a service > without delegating the ability to change its firewall configuration, > you would actually have to go out of your way to also delegate access > to the firewall configuration.
The spec is entirely silent on how these properties are protected. Given that absence, it's inappropriate for a reviewer to assume that they'll be protected properly. - Bill