Read Entry control not applicable to Bind Operations

Michael Ströder <[email protected]> Fri, 20 Apr 2012 18:47:52 +0200
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
HI!

I wonder why RFC 4527 limits the use of the Read Entry control to update
operations (Add, Delete, Modify, ModifyDN).

E.g. the pre-read control could be also useful to read the last login time and
number of failed authc attempts and display it to the user *after* a
successful bind. This is a bit tricky since the appropriate ACLs would have to
be applied when reading the attribute values although the user is not already
bound. But this could be internally handled by the server similar to proxy authz.

Ciao, Michael.

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s (application/pkcs7-signature, 2.3 KB) - not displayed