public keys
by membership certs, ...
ACL is accomplished by
- local name space
- membership certificate
- group certificate