Re: draft-ietf-krb-wg-kdc-model and OIDs

Leif Johansson <[email protected]> Tue, 31 Jul 2012 18:39:53 +0200
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 07/31/2012 03:55 PM, Nico Williams wrote:
> On Tue, Jul 31, 2012 at 3:49 AM, Sam Hartman
> <[email protected]> wrote:
>> Why do we have these OIDs registered here? It seems like the OID
>> should name a specific set of policy objects with well defined
>> semantics and encoding. This draft doesn't get to that level of
>> detail. Wouldn't it be better to defer that to schema  and/or
>> implementation documents?
> 
> Agreed: this document doesn't specify LDAP schema, therefore it 
> shouldn't allocate OIDs for LDAP schema.  Other metaschemas might
> not require OIDs either, and anyways, it's really only LDAP that we
> need OIDs for in the Internet standards context.
> 
> Nico --
> 

I would tend to agree - but note that the information model includes an
identifier as part of the attributes associated with a policy "object"
so as it stands now, a schema has to assign some form of identifier.

If we drop the SHOULD requirement on the specific OIDs we could perhaps
stick something like this in there before the list of standard policies:

"A policy is identified by a unique identifier. It is expected that
implementations of this specification assign globally unique identifiers
(eg an OID or URI) to the following standard policies in accordance with
best-practice for identifier-management for the schema-language used:"

	Cheers Leif

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAlAYClkACgkQ8Jx8FtbMZndb6wCgx1kv9iaHakGhedtCnJmFKatT
7GAAn0LH68zt4OmmzmlS3Gt8jaDNXyMd
=6kRl
-----END PGP SIGNATURE-----
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg