Re: KDC model and atomicity

Leif Johansson <[email protected]> Tue, 26 Jun 2012 11:57:56 +0200
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 06/25/2012 06:39 PM, Sam Hartman wrote:
>>>>>> "Jeffrey" == Jeffrey Hutzelman <[email protected]> writes:
> 
> 
> Jeffrey> That's a valid point.  What I _don't_ want to see is a
> single attribute Jeffrey> with vaguely-defined semantics, such that
> every KDC implementation Jeffrey> includes the attribute but they
> all mean something different with no way Jeffrey> to tell what is
> meant.  I'd rather not have a standardized attribute at Jeffrey>
> all then end up in that situation.
> 
> I agree with the above.
> 
> 
> Jeffrey> I think we have agreement that we don't expect attributes
> exposing the Jeffrey> state of a lockout or throttling mechanism to
> be writeable (with the Jeffrey> possible exception of a "locked"
> attribute that could be used to reset Jeffrey> the entire state).
> So, any such attributes...
> 
> 
> Hmm.  Another concern I have mostly about process is that this
> seems like a very late point in the process to be introducing the
> concept of read-only attributes into the information model. It
> seems like working through the semantics of that could be tricky.
> 
> In another message, Nico said that it seems important to have a way
> to unlock a principal. I agree with that; that seems fairly
> important functionality to have standardized admin clients.

I agree with all of the above. It seems to me that one way to proceed
is to bake 1.0 now and start work on a next revision where we work out
the details of access-levels on attributes, atomicity etc assuming
there is enough comitment to do so from the WG.

	Cheers Leif

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk/ph6QACgkQ8Jx8FtbMZneKngCgwBy/kEF/8VIl/QaVIWlEA4zr
nioAn3XRddci7QnFSdstABVXREqRAHxf
=7b8N
-----END PGP SIGNATURE-----
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg