Re: Schema for posixGroup successor (RFC 2307 bis)

Michael Ströder <[email protected]> Thu, 12 Feb 2015 12:17:43 +0100
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
Andrew Findlay wrote:
> On Wed, Feb 11, 2015 at 10:58:31AM +0100, Michael Ströder wrote:
> 
>> To preserve backwards compability I'd like to propose the following:
>>
>> ( <OID TBD>
>>   NAME 'posixGroup2'
>>   DESC '<TBD>'
>>   SUP ( groupOfEntries $ posixGroup )
           ^^^^^^^^^^^^^^
>>   STRUCTURAL )
> 
> That's a very cunning plan, but I am not sure that it will work...
> [..]
> Thus I think that your new class would have *more* mandatory
> attributes than either of its superiors:
> 
> 	MUST ( member $ cn $ gidNumber )
> 
> Not quite the point as we really want member to be optional.

Hey Andrew, *you* should really remember why you wrote
draft-findlay-ldap-groupofentries ! ;-]

Ok, you've overlooked that I wrote 'groupOfEntries' instead of 'groupOfNames'.

In draft-howard-rfc2307bis-02 'posixGroup' is declared as AUXILIARY, a change
which is forbidden according to Kurt's IANA rules.  And the draft contains a
declaration of 'groupOfMembers' which is pretty much the same as
'groupOfEntries'.  We will sort that out...

> Looking through the common schemas it seems that multiple inheritance
> is extremely rare, so I wonder whether all servers would even agree on
> how it works...

It works for me. :-)

Ok, it works in OpenLDAP since years.  We could send a poll ot ldapext and
ldapbis mailing lists which server products officially support multiple
inheritance.

Ciao, Michael.

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s (application/pkcs7-signature, 4.2 KB) - not displayed