Re: KDC model and atomicity

Sam Hartman <[email protected]> Mon, 25 Jun 2012 12:39:48 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Jeffrey" == Jeffrey Hutzelman <[email protected]> writes:


    Jeffrey> That's a valid point.  What I _don't_ want to see is a single attribute
    Jeffrey> with vaguely-defined semantics, such that every KDC implementation
    Jeffrey> includes the attribute but they all mean something different with no way
    Jeffrey> to tell what is meant.  I'd rather not have a standardized attribute at
    Jeffrey> all then end up in that situation.

I agree with the above.


    Jeffrey> I think we have agreement that we don't expect attributes exposing the
    Jeffrey> state of a lockout or throttling mechanism to be writeable (with the
    Jeffrey> possible exception of a "locked" attribute that could be used to reset
    Jeffrey> the entire state).  So, any such attributes...


Hmm.  Another concern I have mostly about process is that this seems
like a very late point in the process to be introducing the concept of
read-only attributes into the information model.
It seems like working through the semantics of that could be tricky. 

In another message, Nico said that it seems important to have a way to
unlock a principal.
I agree with that; that seems fairly important functionality to have
standardized admin clients.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg