Re: why posixAccount MUST contain 'cn'?

Michael Ströder <[email protected]> Sun, 14 Dec 2014 23:49:35 +0100
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
Kurt Zeilenga wrote:
> 
>> On Dec 14, 2014, at 12:19 PM, Michael Ströder <[email protected]> wrote:
>>
>> Kurt Zeilenga wrote:
>>>
>>>> On Dec 14, 2014, at 11:42 AM, Michael Ströder <[email protected]> wrote:
>>>>
>>>> Kurt Zeilenga wrote:
>>>>>
>>>>>> On Dec 14, 2014, at 9:35 AM, Michael Ströder <[email protected]> wrote:
>>>>>>
>>>>>> Kurt Zeilenga wrote:
>>>>>>>> I'd be in favour of relaxing this to MAY cn in RFC2307bis.
>>>>>>>
>>>>>>> See BCP 118 [RFC 4521], Section 5 concerning IETF rules for changing previously published schema definitions.
>>>>>>
>>>>>> Yes, but RFC2307bis also changes posixGroup schema.
>>>>>
>>>>> Don’t expect I-Ds which violate BCPs to become RFCs.
>>>>
>>>> Are you saying that draft-howard-rfc2307bis will never become an RFC because
>>>> it changes the declaration of 'posixGroup' ('member' instead of 'memberUID')
>>>> defined in the experimental RFC 2307?
>>>
>>> I won’t say “never” as well BCPs themselves are subject today…   but I can
>>> tell you that I, as the IESG’s appointed LDAP registries expert to IANA,
>>> have and will reject requests to register LDAP parameters which purport to
>>> modify previously published LDAP schema definitions.  Of course, such
>>> actions are appealable.
>>
>> So RFC2307bis must start over with completely new NAMEs
>> for e.g. posixGroup?
> 
> Yes, as posixGroup has already been published, if you don’t want to use it
> as published, you need to create a replacement for it… and that replacement
> has to have a new OID and a new NAME.

Hmm, I respect that decision and thanks for the clear words.

But it's clearly a problem with all the existing NSS LDAP client
implementations/deployments which already use RFC2307bis posixGroup>member
draft schema.

So the question is: How to correctly push that forward?

Some more nitpicking:
The RFC 2307 defined OIDs are not listed here only the base OID:
http://www.iana.org/assignments/ldap-parameters/ldap-parameters.xhtml

Ciao, Michael.

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s (application/pkcs7-signature, 4.2 KB) - not displayed