1. allow some clients in auth file 2. run chisel server with that auth file 3. clients connect, OK 4. delete clients from the auth file 5. clients still use their old established connections - BAD 6. new connections from the same clients rejected - GOOD