Re: DBIS commentary

Jordan Brown <[email protected]> Thu, 3 Dec 2015 09:00:24 -0800
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8578509541738715171==
Content-Type: multipart/alternative;
 boundary="------------060409080206060504060102"

This is a multi-part message in MIME format.
--------------060409080206060504060102
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/3/2015 2:35 AM, Bannister, Mark wrote:
>
>> It doesn't look like you've got 4876 completely covered, though.  Attr=
ibute=20
>> mapping is only one of the things it does - it also tells the clients =
which=20
>> servers to connect to and what authentication schemes to use.  If you'=
re=20
>> replacing 4876, there should be a plan for replacing that capability.
>
> Yes I=E2=80=99ve not quite understood that.  You need to configure the =
client to talk to=20
> an LDAP server, in order
>
> to obtain a profile that tells it to talk to a different LDAP server in=
stead. =20
> Why would you not just
>
> configure the client to talk to the correct LDAP server in the first pl=
ace? =20
> Please explain the use-case.
>

Centralized reconfiguration.  Your initial configuration is a bootstrap; =
after=20
that, changes in the profile can direct you to use new sets of servers as=
 existing=20
servers are replaced.  Similarly, if you've got PKI or Kerberos infrastru=
cture in=20
place, the profile can tell you to start using it.


--------------060409080206060504060102
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3DUTF-8" http-equiv=3D"Content-Ty=
pe">
  </head>
  <body bgcolor=3D"#FFFFFF" text=3D"#000000">
    <div class=3D"moz-cite-prefix">On 12/3/2015 2:35 AM, Bannister, Mark
      wrote:<br>
    </div>
    <blockquote
cite=3D"mid:[email protected].=
com"
      type=3D"cite">
      <!-- Template generated by Exclaimer Template Editor on 05:35:10 Do=
nderdag, 3 Desember 2015 -->
      <style type=3D"text/css">P.3c364900-31e1-4e3e-bb45-29f58d9a1e7d {
	MARGIN: 0cm 0cm 0pt
}
LI.3c364900-31e1-4e3e-bb45-29f58d9a1e7d {
	MARGIN: 0cm 0cm 0pt
}
DIV.3c364900-31e1-4e3e-bb45-29f58d9a1e7d {
	MARGIN: 0cm 0cm 0pt
}
TABLE.3c364900-31e1-4e3e-bb45-29f58d9a1e7dTable {
	MARGIN: 0cm 0cm 0pt
}
DIV.Section1 {
	page: Section1
}
</style>
      <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DU=
TF-8">
      <meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	color:black;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing
	{mso-style-priority:1;
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";
	color:black;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0cm;
	margin-right:0cm;
	margin-bottom:0cm;
	margin-left:36.0pt;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";
	color:black;}
span.Code
	{mso-style-name:Code;
	mso-style-priority:1;
	font-family:"Courier New";}
p.ae8b49d9-d5d8-4b09-a975-5128f74bda5d, li.ae8b49d9-d5d8-4b09-a975-5128f7=
4bda5d, div.ae8b49d9-d5d8-4b09-a975-5128f74bda5d
	{mso-style-name:ae8b49d9-d5d8-4b09-a975-5128f74bda5d;
	mso-style-priority:99;
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri","sans-serif";
	color:black;}
p.cafa858c-a64a-4018-b357-eb8084b6b267, li.cafa858c-a64a-4018-b357-eb8084=
b6b267, div.cafa858c-a64a-4018-b357-eb8084b6b267
	{mso-style-name:cafa858c-a64a-4018-b357-eb8084b6b267;
	mso-style-priority:99;
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
span.EmailStyle25
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle26
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
      <p>
      </p>
      <div class=3D"WordSection1">
        <blockquote type=3D"cite">It doesn't look like you've got 4876
          completely covered, though.=C2=A0 Attribute mapping is only one=
 of
          the things it does - it also tells the clients which servers
          to connect to and what authentication schemes to use.=C2=A0 If
          you're replacing 4876, there should be a plan for replacing
          that capability.</blockquote>
        <o:p></o:p>
        <p class=3D"MsoPlainText">Yes I=E2=80=99ve not quite understood t=
hat.=C2=A0 You
          need to configure the client to talk to an LDAP server, in
          order<o:p></o:p></p>
        <p class=3D"MsoPlainText">to obtain a profile that tells it to
          talk to a different LDAP server instead.=C2=A0 Why would you no=
t
          just<o:p></o:p></p>
        <p class=3D"MsoPlainText">configure the client to talk to the
          correct LDAP server in the first place?=C2=A0 Please explain th=
e
          use-case.<o:p></o:p></p>
      </div>
    </blockquote>
    <br>
    Centralized reconfiguration.=C2=A0 Your initial configuration is a
    bootstrap; after that, changes in the profile can direct you to use
    new sets of servers as existing servers are replaced.=C2=A0 Similarly=
, if
    you've got PKI or Kerberos infrastructure in place, the profile can
    tell you to start using it.<br>
    <br>
  </body>
</html>

--------------060409080206060504060102--


--===============8578509541738715171==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext

--===============8578509541738715171==--