Re: choosing principal names
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Nico Williams <[email protected]> writes: > On Thu, Oct 6, 2011 at 5:55 PM, Russ Allbery <[email protected]> wrote: >> And, of course, they do. :) OpenLDAP has very extensive support for >> partial disclosure of a record, or even providing entirely different >> data depending on who asks. We use that pretty extensively at Stanford >> because we're very aggressive about data privacy controls. > Have you talked to Simo about this? I haven't, no. We use things like regex matches against entitlement attributes in our LDAP ACLs at Stanford to selectively release particular entitlements to clients that are only authorized to see some entitlements, which is probably the most directly applicable example. (We also have lots of privacy-based ACLs that restricts view of things like phone numbers and addresses based on other attributes that hold user-configured privacy settings, but that's not as directly relevant to the current conversation.) -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>