revised WG charter proposal

"Chris Apple" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>
Here's the latest revision incorporating several changes received both on
the list
and privately. Also note the accomplishment of several milestones since the
last proposal was posted to the list.

Because of the upcoming holiday in the US, lets evaluate and discuss this
version until 1700 ET US time on Tuesday, November 27, 2001.

Silence means consent.

Please read and post comments to the WG mailing list.

Chris Apple

Who has recently concluded that life is mostly and rightfully about
wondering what to make for dinner for family and friends.

LDAP Duplication/Replication/Update Protocols (ldup)

Last Modified: 16-Nov-01

Chair(s):

Chris Apple <[email protected]>
John Strassner <[email protected]>

Applications Area Director(s):

Ned Freed <[email protected]>
Patrik Faltstrom <[email protected]>

Applications Area Advisor:

Patrik Faltstrom <[email protected]>

Mailing Lists:

General Discussion:[email protected]
To Subscribe: [email protected]
In Body: subscribe
Archive: http://www.imc.org/ietf-ldup/

Description of Working Group:

As LDAPv3 becomes more widely deployed, replication of data across
servers running different implementations becomes an important part
of providing a distributed directory service. However, the LDAPv3
community, to date, has focused on standardizing the client-server
access protocol. Therefore, this group will standardize master-slave
and multi-master LDAPv3 replication as defined below:

o Multi-Master Replication - A replication model where entries can
  be written and updated on any of several replica copies, without
  requiring communication with other masters before the write or
  update is performed.

o Master-Slave, or Single-Master Replication - A replication model
  that assumes only one server, the master, allows write access to
  the replicated data. Note that Master-Slave replication can be
  considered a proper subset of multi-master replication.

The WG's approach is to first develop a set of requirements for
LDAPv3 directory replication and write an applicability statement
defining scenarios on which replication requirements are based.
An engineering team was formed consisting of different vendors
and the co-chairs in order to harmonize the existing approaches
into a single standard approach. All of these have been accomplished
during the pre-working group stage.

The new replication architecture support all forms of replication
mentioned above. Eight areas of working group focus have been
identified through LDUP Engineering Team discussions and mailing
list discussion, each leading to one or more documents to be published:

o LDAPv3 Replication Architecture

   This documents a general-purpose LDAPv3 replication architecture,
   defines key components of this architecture, describes how these
   key components functionally behave, and describes how these
   components interact with each other when in various modes of
   operation.

o LDAPv3 Replication Information Model

   Defines the schema and semantics of information used to operate,
   administer, maintain, and provision replication between LDAPv3
   servers. Specifically, this document will contain common schema
   specifications intended to facilitate interoperable
   implementations with respect to:

      + replication agreements

      + consistency models

      + replication topologies

      + managing deleted objects and their states

      + administration and management

o LDAPv3 Replication Information Transport Protocol

   LDAPv3 extended operation and control specifications required to
   allow LDAPv3 to be used as the transport protocol for information
   being replicated

o LDAPv3 Mandatory Replica Management

   Specifications required to allow administration, maintenance, and
   provisioning of replicas and replication agreements. These
   specifications may take the form of definitions for LDAPv3
   extended operations, controls, and/or new schema elements.

o LDAPv3 Update Reconciliation Procedures

   Procedures for detection and resolution of conflicts between the
   state of multiple replicas that contain information from the same
   unit of replication.

o LDAPv3 Replication Usage Profile

   Including the LDAPv3 Replication Architecture, Information Model,
   Protocol Extensions, and Update Reconciliation Procedures for:

      + LDAPv3 Master-Slave Directory Replication

      + LDAPv3 Multi-Master Directory Replication

o LDAPv3 Client Update

   A protocol that enables an LDAP client to synchronize with the
   content of a directory information tree (DIT) stored by an LDAP
   server and to be notified about the changes to that content.

o LDAPv3 Access Control Issues

   Replication using heterogeneous LDAPv3 servers is dependent on
   resolving LDAPv3 access control issues, which are currently in
   the domain of another Applications Area working group. RFC 2820,
   Access Control Requirements for LDAP, was produced by that working
   group. However, this working group has elected to close prior to
   establishing consensus on other documents, such as an Access Control
   Model specification for LDAPv3. Such documents are necessary for
   LDUP to meet certain replication requirements documented by the
   LDUP WG. Thus, the remaining access control work and the latest
   revision of the access control model Internet Draft produced by
   the originating working group as starting point for continuing
   the work in the LDUP WG.

The work being done in the LDUP WG should be coordinated to the
closest extent possible with similar work being done in the ITU.
This is necessary both because LDAP depends on X.500 and because
it makes sense from an operational perspective.


Goals and Milestones:

Done    Submit I-D on LDAPv3 Directory Replication Requirements.

Done    Submit Internet-Draft on LDAPv3 Replication Information Model.

Done    Submit I-D on LDAPv3 Update Reconciliation Procedures.

Done    Revise I-D on LDAPv3 Directory Replication Requirements.

Done    Revise I-D on LDAPv3 Replication Architecture.

Done    Revise I-D on LDAPv3 Replication Architecture.

Done    Revise I-D on LDAPv3 Replication Information Model.

Done    Submit I-D on LDAPv3 Replication Information Transport Protocol.

Done    LDAPv3 Directory Replication Requirements I-D goes to WG Last
        Call as Informational.

Done    Submit I-D on LDAPv3 Mandatory Replica Management.

Done Submit I-D on General LDUP Usage Profile.

Done Submit I-D on LDAPv3 Operations Framing.

Done I-D on LDAPv3 Extended Operations for Framing goes to WG Last
        Call as Proposed Standard.

Done Revise I-D on LDAPv3 Replication Information Transport Protocol.

Done Revise I-D on General LDUP Usage Profile.

Done Revise I-D on LDAPv3 Mandatory Replica Management.

Dec 01 LDAPv3 Client Update Protocol I-D goes to WG Last Call as
        Proposed Standard.

Dec 01 Rename the Access Control Model for LDAPv3 document to become an
 LDUP WG deliverable.

Jan 01  Revise Access Control Model for LDAPv3 I-D.

Jan 01  Submit an I-D on LDAPv3 Authentication Identity to Authorization
        Identity Mapping Scheme.

Feb 02 LDAPv3 Replication Architecture I-D goes to WG Last Call as
        Informational.

Mar 02 LDAPv3 Update Reconciliation Procedures I-D goes to WG Last Call
        as Proposed Standard.

Mar 02 LDAPv3 Replication Information Model I-D goes to WG Last Call as
        Proposed Standard.

Mar 02 LDAPv3 Replication Information Transport Protocol I-D goes to WG
        Last Call as Proposed Standard.

Mar 02  Revise I-D on Authentication Identity to Authorization Identity
 Mapping Scheme for LDAPv3.

Apr 02  Access Control Model for LDAPv3 I-D goes to WG Last Call as
        Proposed Standard.

May 02  Authentication Identity to Authorization Identity Mapping Scheme for
 LDAPv3 I-D goes to WG Last Call as Proposed Standard.

Jun 02 LDAPv3 Mandatory Replica Management I-D goes to WG Last Call as
        Proposed Standard.

Jul 02 Re-evaluate Charter and Milestones.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.