Re: empty-groupOfNames-issue

Simo Sorce <[email protected]> Fri, 04 Dec 2015 12:22:56 -0500
Newsgroups gmane.ietf.ldapext
Organization Red Hat, Inc.
Message-ID <[email protected]>
On Fri, 2015-12-04 at 16:34 +0000, Andrew Findlay wrote:
> On Fri, Dec 04, 2015 at 10:44:47AM -0500, Simo Sorce wrote:
> 
> > An auxiliary class may be a better choice for a standard.
> 
> Yes: I also prefer to define aux classes where possible.
> groupOfEntries was defined STRUCTURAL to make it a drop-in
> replacement for groupOfNames.
> 
> If we were starting from a clean slate we might just define:
> 
>      ( 1.2.826.0.1.3458854.2.1.1.666 NAME 'membershipObject'
>             SUP top
>             AUXILIARY
>             MAY ( member )
>      )
> 
> and allow designers to apply it to any appropriate structural class.
> Following that to its logical conclusion would give almost 1:1
> correspondence between objectclasses and attributetypes, which most
> would probably regard as over-normalisation!
> 
> In fact I think groups are very reasonable STRUCTURAL objects,
> as the concept of groups has such broad application. Where I might argue
> with the current definition of groupOfNames/groupOfEntries is the list
> of other descriptive attributes (why should groups have a
> businessCategory but no displayName for example?)

I tend to agree, but posixGroup is structural ... sigh :)

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York