Re: DRAFT Minutes of the 51st meeting for your review
Richard Huber <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
I'd like to address the comment about the wording in the Access Control Model draft that says "This model does not (and cannot) fully specify the behavior of the Access Control Model in a distributed environment ..." This text is not talking about REPLICATED environments (in fact, there is already wording in the document that says "These same flows on the wire apply when ACI is transmitted during replication."; we certainly see replicated environments as an area where consistent access controls are needed). The comment about DISTRIBUTED environments was addressing the issues that arise when a replica does not hold the entire DIT, and in particular the case where a replica does not hold the root of the DIT. Since access rights at a given point in the tree may depend on access controls higher in the tree, there needs to be a way to check the access controls in parts of the tree not held in the replica. Note that these issues arise because of "partitioning" (servers that hold only part of the DIT) regardless of whether replication is used. The issue was discussed in more depth in Ed Reed's (now expired) draft-reed-ldup-inheritance-00.txt (the minutes of a bar-BOF in San Diego). This is one of those cases where I wish IDs were permanent; the draft doesn't solve the problem but it contains a useful description of it with recommendations towards a solution; it would be nice to have this recorded. It seems that the current text on distributed environments causes confusion - the Access Control Model draft should be clearer about the issues of distributed environments (and what we mean by that term). We will improve this in the next version. Rick Huber John Strassner wrote: > Greetings LDUPers, > > below please find the draft meeting minutes for the London meeting. > Apologies for the late delay - apparently this was never successfully > delivered. Please submit any comments and corrections to me asap so > that I can include these in the official minutes. And thanks > presenters, I already have all of your slides for inclusion. > > regards, John Strassner and Chris Apple > LDUP WG Co-Chairs > Lots of stuff omitted. > > 9) LDAP Access Control Model Work > > The focus of this agenda item was to ferret out any concerns that > people had on the ACM work to ensure that these would not affect LDUP. > > It was noted that the model document does not define how access > control will work in a replicated environment. The LDUP general > usage profile document is a good job of indicating lots of things > (besides access control) that are affected when replication is added > to the environment. > > Open question to group by Chris Apple with respect to what > outstanding problems people have with the access control model > and replication? > > Kurt: model document still lists access control as not defined > how access control works in a replicated environment. There is > a need for LDUP folks to read and comment on the current > ACL model draft. Lot's more stuff omitted.