Re: choosing principal names

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization The Eyrie
Message-ID <[email protected]>
Nico Williams <[email protected]> writes:
> On Thu, Oct 6, 2011 at 5:55 PM, Russ Allbery <[email protected]> wrote:

>> And, of course, they do.  :)  OpenLDAP has very extensive support for
>> partial disclosure of a record, or even providing entirely different
>> data depending on who asks.  We use that pretty extensively at Stanford
>> because we're very aggressive about data privacy controls.

> Have you talked to Simo about this?

I haven't, no.

We use things like regex matches against entitlement attributes in our
LDAP ACLs at Stanford to selectively release particular entitlements to
clients that are only authorized to see some entitlements, which is
probably the most directly applicable example.  (We also have lots of
privacy-based ACLs that restricts view of things like phone numbers and
addresses based on other attributes that hold user-configured privacy
settings, but that's not as directly relevant to the current
conversation.)

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.