Re: KDC model and atomicity
Sam Hartman <[email protected]> Tue, 26 Jun 2012 06:57:03 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Jeffrey" == Jeffrey Hutzelman <[email protected]> writes: Given that, a minimalist approach would be to: Mark 4.1.1.5 through 4.1.1.8 as OPTIONAL. * Add a note to 4.1.1.4 indicating that schemas MUST have a mechanism for re-enabling a principal that has been disabled through operational mechanisms such as account lock out. Rationale: Nothing in 4.1.1.5-8 actually talks about account lock out. This discussion has actually made it clear that these attributes are kind of useless for account lock out mechanisms. We could remove them; I don't object to that, but doing so is unnecessary given anything in this discussion. A schema might decide they are useless or too hard to implement. Specifying how you re-enable a principal is tricky and schema-dependent so we should leave it to schemas but mandate that it must be possible. I'm not particularly attached to this proposal. It's simply intended to be something that minimally changes the document and responds to comments made here. I certainly have no objection to it, but would be happy with other options to. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg