Re: Correction to Last Call posting
"Kurt D. Zeilenga" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
This message mostly reiterates previously raised issues. Section 3: Interoperability among directories using LDUP replication may be limited for implementations that add semantics beyond those specified by the LDAP core documents (RFC 2251-2256, 2829, 2830). I note that Interoperability among directories using LDUP replication may also be limited for implementations which implement different subsets of the semantics defined in the LDAP "core" specification. For example, one implementation may support subtyping another not. Another may require ;binary for some standard track attribute while another disallows ;binary for same. As an alternative to adding a clarification to the statement (as I would prefer), removing the statement (as it doesn't place a requirement upon LDUP) would be acceptable. G9. Sentence 1. LDAP replication SHOULD support replication of directoryOperation and distributedOperation attribute types defined in standards track LDAP extensions. I note that Dynamic Directory Services Extensions (RFC 2589) standard track may be quite difficult to support. G9. Sentence 2. Future standards track specifications SHOULD include a "Replication Considerations" section which indicates how and whether the new feature operates in a replicated environment. I note that this is not a requirement upon LDUP but a requirement upon future standard track specifications to detail how to operate in yet specified replicated environment. I believe this should be reworded without use of a RFC 2119 imperative or other wording implying this is a requirement which future specifications need to consider. If such a requirement were needed to be stated, it should be stated in a document (BCP?) detailing guidelines to developers of LDAP extensions. I note that such a guideline is under development. M5. LDAP replication MUST NOT require all copies of the replicated information to be complete copies of the replicated object. The model MUST support Partial Replicas. I assume this applies to copies, not to the original. That is, I assume that LDAP replication MAY require some master (if not all masters) to hold a complete instance of the object. Some clarification here may be appropriate. Security Considerations: "As noted in Section 3, security may be impacted..." Section 3 makes no statement about security. It makes a statement about interoperability. Editorial comments: The RFC 2119 paragraph should be moved from the Abstract to end of section 1 or added to section 2, which details terminology used. "privacy" (S6,S7) should be replaced with "confidentiality".