| Newsgroups |
gmane.ietf.ldapext |
| Message-ID |
<[email protected]> |
Mark R Bannister wrote:
> On 28/01/2015 14:14, Simo wrote:
>> It hurts me to curb enthusiasm, but I think your drafts are not a step
>> forward, at most a step sideways, and ignore what's out there right now.
>
> Given that they were written to fix specific deficiencies in RFC2307bis
> that were causing pain in a number of very large enterprises I have worked
> for, I don't see how they could be considered a step sideways.
Maybe I did not look closely enough. Could you please point me to some text
describing the specific deficiencies you solved in more detail?
> When you say my drafts ignore what's out there right now, what are they
> ignoring?
> [..]
>> The software out there and now expect either RFC2307 or at most
>> RFC2307bis (and then really they just test against Active Directory's
>> schema and things happen to mostly work). Any other schema would just
>> fail to be useful for a generic LDAP server.
>
> To what software do you refer specifically?
I think like me Simo also meant the client side.
> NSS is a big subscriber, and I've addressed that one. Then there is the
> automounter, and sudo, and really only a handful of others all of which can
> be fixed to use a more modern schema.
>
> I'm not going to spend 18 months developing DBIS to be turned away because
> software
> doesn't support it. Of course software doesn't support it - yet - it's new!
But the question is whether there's a solution which is compatible to existing
client-side software. I know you're working on PAM/NSS clients but the
question is whether you can install that on legacy Unices or strange applicances.
My approach is to lower the configuration level the client has to support by
filtering what's delivered to the client at the LDAP server.
Ciao, Michael.