Re: password policy: multiple subentries, multiple password attributes, ....

Howard Chu <[email protected]>
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
Kurt Zeilenga wrote:
> The spec specifically allows for an user entry to be controlled by
> multiple
policies (each for a different password attribute) but then defines
pwdPolicySubentry to be single-valued.

> It seems to me that the text as a whole doesn't really well consider the
implications of multiple applicable password policies.

I'm pretty sure the intention has always been for only a single policy to 
apply to any given entry. Note that it already explicitly requires only a 
single password value to be present in any entry.

When you see that the spec allows for a different password attribute to be 
used, I take this to mean that within an entire directory, multiple password 
attributes may be used. But for any given entry, it must have only one 
password value, regardless of which attribute carries it.

> In our current implementation, we do implement 5.3.1, and mandate that
> only
a single password policy be applicable to a given user.
>
> We currently looking at userPassword v. authPassword implications with
regard to auto-migration, as we're now supporting the latter for SCRAM
authentication. I think we'll assume that if both are present in an entry,
they represent the same same user password. We'll like need to support both
RFC 2307 hashing and in conjunction with SCRAM authPassword hashing so that
users can use either TLS+SimpleBind(WithPassword) or SCRAM.
>
> I don't see the value of having two disjoint password policies, one for
> each
attribute. What I believe our customers will demand is an unified password
policy covering both of these attributes. (I can see a possible desire to
support a disjoint password policy covering passwords for directory
application specific passwords, such as when one has a different directory
password from say an email password stored in the directory. However, our
customers which have different passwords for different directory applications
tend to rely on multiple entries per user, one per directory application (with
service-level authorization restrictions), not multiple passwords attributes
in a single entry.)

> -- Kurt

-- 
   -- Howard Chu
   CTO, Symas Corp.           http://www.symas.com
   Director, Highland Sun     http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP  http://www.openldap.org/project/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.