password policy vs. shadowing/caching

Kurt Zeilenga <[email protected]>
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
Not only does the spec continue to suffer from various issues in face of shadowing/caching, additional issues in this area have been introduced by features such as account idling.

Account idling relies on shared knowledge across a set of DSAs of last successful login, and nothing in LDAP/X.500 ensures such shared knowledge can be maintained.

I favor a base specification(s) which details policy mechanisms specifically designed to operate in a traditional LDAP/X.500 model (each entry held by one master, possibly multiple shadow and caching DSAs) without any reliance on distributed operations and possibly additional specifications (possibly as appendices to the base) discussing how the base specification could be enhanced through the use of distributed operations and other yet-to-be-specified extensions (to the protocol or models).

-- Kurt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.