Re: DBIS - new IETF drafts
Michael Ströder <[email protected]> Wed, 08 Jan 2014 19:57:24 +0100
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
Arthur de Jong wrote: > I personally like the use of flat names to describe group membership. It > makes the semantics much simpler than dealing with things like the > member or uniqueMember attribute (at least from a client implementation > perspective). > > The use of distinguished names may seem more logical from an LDAP > structure point of view, but you will have to dereference any DN to a > user name for building up a group entry resulting in potentially a lot > of search operations to get complete data. Using DNs allows to implement server-side access control. I'm not a friend of letting client-side demons enforce the access control because if a machine got hacked the attacker can find out more about the infrastructure. Ciao, Michael. _______________________________________________ Ldapext mailing list [email protected] https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s
(application/pkcs7-signature, 2.3 KB) - not displayed