Re: revised WG charter proposal

"Timothy Hahn" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>
Hello,

Excerpt from Proposed WG charter:

o LDAPv3 Access Control Issues

   Replication using heterogeneous LDAPv3 servers is dependent on
   resolving LDAPv3 access control issues, which are currently in
   the domain of another Applications Area working group. RFC 2820,
   Access Control Requirements for LDAP, was produced by that working
   group. However, this working group has elected to close prior to
   establishing consensus on other documents, such as an Access Control
   Model specification for LDAPv3. Such documents are necessary for
   LDUP to meet certain replication requirements documented by the
   LDUP WG. Thus, the remaining access control work and the latest
   revision of the access control model Internet Draft produced by
   the originating working group as starting point for continuing
   the work in the LDUP WG.

My opinion on whether the workgroup should solve the access control model 
specification is as follows:

a) in order for replication to take place and ensure that data replicated 
in two different server instances is not accessed inappropriately in 
either one of the server instances, the replication model MUST rely on 
some statement about access control.  I would expect that these statements 
would be covered in the "Security Considerations" section of the drafts 
and RFCs (among other places).
b) the past attempts by LDAPext to establish consensus around any 
particular access control model have not been successful.  Progress has 
been made, to be sure, but in my opinion, we are not yet near a "final 
solution" with consensus.
c) I do not believe that LDUP requires a FULL access control model 
specification in order to proceed with a "secure" solution.  By this, I 
believe that the two problems ARE factorable.
d) There are elements of the current access control model specification 
that could help us "factor" the problems - namely the notion in the 
current ACM model that each ACI is defined by some OID and the particular 
ACI(s) that a server supports/uses is held in the root DSE.

I feel that the LDUP WG SHOULD pursue a specification of how access 
control "frameworks" are published (without specifying/defining any 
particular access control model design).  This allows for two (or n) 
servers to establish what access control models are defined/implemented on 
any particular server and for those servers to figure out IF they can 
"agree" on a ACI model to use.

With this "framework" agreed upon, LDUP can state in its "security 
considerations" that for secure environments, replicating servers MUST 
implement and use "compatible" ACI models - but LDUP need NOT define any 
particular model be employed.  I believe that this allows the access 
control to be "factored" from the replication problem.

In summary, I feel that LDUP should NOT take on the "whole" access control 
problem (as is attempted in the current ACM draft from the LDAPext working 
group).  Rather, LDUP should take on work to define a "framework" in which 
different ACI models can be defined and published, and then LDUP should 
state that "compatible" access control models MUST be used for secure 
replication.

Regards,
Tim Hahn

Internet: [email protected]
Internal: Timothy Hahn/Endicott/IBM@IBMUS or IBMUSM00(HAHNT)
phone: 607.752.6388     tie-line: 8/852.6388
fax: 607.752.3681
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.