Re: empty-groupOfNames-issue

Andrew Findlay <[email protected]> Fri, 4 Dec 2015 16:34:29 +0000
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
On Fri, Dec 04, 2015 at 10:44:47AM -0500, Simo Sorce wrote:

> An auxiliary class may be a better choice for a standard.

Yes: I also prefer to define aux classes where possible.
groupOfEntries was defined STRUCTURAL to make it a drop-in
replacement for groupOfNames.

If we were starting from a clean slate we might just define:

     ( 1.2.826.0.1.3458854.2.1.1.666 NAME 'membershipObject'
            SUP top
            AUXILIARY
            MAY ( member )
     )

and allow designers to apply it to any appropriate structural class.
Following that to its logical conclusion would give almost 1:1
correspondence between objectclasses and attributetypes, which most
would probably regard as over-normalisation!

In fact I think groups are very reasonable STRUCTURAL objects,
as the concept of groups has such broad application. Where I might argue
with the current definition of groupOfNames/groupOfEntries is the list
of other descriptive attributes (why should groups have a
businessCategory but no displayName for example?)

Andrew
-- 
-----------------------------------------------------------------------
|                 From Andrew Findlay, Skills 1st Ltd                 |
| Consultant in large-scale systems, networks, and directory services |
|     http://www.skills-1st.co.uk/                +44 1628 782565     |
-----------------------------------------------------------------------