Re: choosing principal names
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Nico Williams <[email protected]> writes: > On Thu, Oct 6, 2011 at 5:37 PM, Russ Allbery <[email protected]> wrote: >> I think LDAP lookups are superior to the PAC in every possible respect >> except for performance and the requirement to contact a central service >> (PAC data can work in a more decoupled network environment). > Except for Simo's use case, where the application server can't talk to > the client principal's LDAP server for policy reasons. That's what I mean in part by a decoupled network environment. > I suppose that if LDAP servers implemented suitable filtering policy > languages, then the privacy issues could be addressed without a PAC. And, of course, they do. :) OpenLDAP has very extensive support for partial disclosure of a record, or even providing entirely different data depending on who asks. We use that pretty extensively at Stanford because we're very aggressive about data privacy controls. -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>