Re: DBIS - new IETF drafts

Michael Ströder <[email protected]> Wed, 08 Jan 2014 19:57:24 +0100
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
Arthur de Jong wrote:
> I personally like the use of flat names to describe group membership. It
> makes the semantics much simpler than dealing with things like the
> member or uniqueMember attribute (at least from a client implementation
> perspective).
> 
> The use of distinguished names may seem more logical from an LDAP
> structure point of view, but you will have to dereference any DN to a
> user name for building up a group entry resulting in potentially a lot
> of search operations to get complete data.

Using DNs allows to implement server-side access control. I'm not a friend of
letting client-side demons enforce the access control because if a machine got
hacked the attacker can find out more about the infrastructure.

Ciao, Michael.

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s (application/pkcs7-signature, 2.3 KB) - not displayed