Re: I-D ACTION:draft-zeilenga-ldap-relax-00.txt
Michael Ströder <[email protected]> Fri, 01 Jul 2011 20:16:22 +0200
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
Kurt Zeilenga wrote: > On Jul 1, 2011, at 9:13 AM, Michael Ströder wrote: >> I'd also suggest that relaxable attribute types are announced with X-RELAX in >> the subschema subentry so that a schema-aware client can determine which >> attributes to make editable in case the control is in effect. > > I rather not get into detail advertisement of what DSAs will or will not > relax when this control is used. This is a problem that not easily > solved. > > It's basically assumed that this control will be used by the DSA > administrator who as knowledge of what will get relaxed when it's used. What problems are not easily solved? The behaviour of web2ldap's UI already changes if this control is in effect. E.g. input fields of relaxable attributes are enabled if the user turns on the relax rules control. Obviously I'd prefer to look at the subschema to find out which attributes can be relaxed instead of maintaining a hard-coded list in web2ldap's code. > It's not intended to be used generally. Yes, the control is for the expert DSA admin. But a good admin tool guides the admin user too. ;-) > I see that some implementations rely use of this relax control by users who > might no be theDSA administrators to overcome poor design of certain > LDAP/X.500 "policy" extensions. Such use is beyond the scope of this > extension. I would rather see better designs in these policy extensions. Yes, so please comment in detail on the mailing lists where you saw this. ;-) Ciao, Michael.