Re: empty-groupOfNames-issue
Simo Sorce <[email protected]> Fri, 04 Dec 2015 12:22:56 -0500
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Organization | Red Hat, Inc. |
| Message-ID | <[email protected]> |
On Fri, 2015-12-04 at 16:34 +0000, Andrew Findlay wrote: > On Fri, Dec 04, 2015 at 10:44:47AM -0500, Simo Sorce wrote: > > > An auxiliary class may be a better choice for a standard. > > Yes: I also prefer to define aux classes where possible. > groupOfEntries was defined STRUCTURAL to make it a drop-in > replacement for groupOfNames. > > If we were starting from a clean slate we might just define: > > ( 1.2.826.0.1.3458854.2.1.1.666 NAME 'membershipObject' > SUP top > AUXILIARY > MAY ( member ) > ) > > and allow designers to apply it to any appropriate structural class. > Following that to its logical conclusion would give almost 1:1 > correspondence between objectclasses and attributetypes, which most > would probably regard as over-normalisation! > > In fact I think groups are very reasonable STRUCTURAL objects, > as the concept of groups has such broad application. Where I might argue > with the current definition of groupOfNames/groupOfEntries is the list > of other descriptive attributes (why should groups have a > businessCategory but no displayName for example?) I tend to agree, but posixGroup is structural ... sigh :) Simo. -- Simo Sorce * Red Hat, Inc * New York