Re: Fwd: Manual Post Requested for draft-howard-rfc2307bis
Howard Chu <[email protected]>
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
Ralf Haferkamp wrote: > Am Sonntag 09 August 2009 23:41:42 schrieb Howard Chu: >> I guess this will show up in a couple of days. >> >> Major differences from version 01 of the rfc2307bis document: >> >> 1) Added host and hostos attribute options to allow system-specific values >> for attributes when needed. (E.g. to accommodate different homeDirectory >> locations on various machines.) >> >> 2) Added integerOrderingMatch ORDERING rules to attributes with integer >> syntax. Admins frequently need to search for things like (uidNumber>=1000) >> and the lack of the ORDERING rules was a great impediment. >> >> 3) Added new groupOfMembers structural objectclass with "member" as an >> optional attribute, to support groups with zero members. This class should >> be used whenever a structural group class is needed. The use of >> groupOfUniqueNames (and groupOfNames) is deprecated. > > I wonder if it might be better to leave details about which structural > objectclass should be used for groups out of this document. For implementors > it should be enough to know that "member" is used for group members and > "posixGroup" is the auxillary objectclass to look for. > The definition of groupOfMembers might then better be handled in a separate > document. As I think it is useful of other purposes than described here as > well. Right. Given the long discussion about group objectclasses we had on this list a while back, it's obviously something that has further effects. I had forgotten if there was any conclusion to those discussions when I was editing this draft, and only remembered it afterward. > Additionally I wonder if the "memberUid" Attribute should be removed > completely or at least be documented as being deprecated. -- -- Howard Chu CTO, Symas Corp. http://www.symas.com Director, Highland Sun http://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/