Re: revised WG charter proposal

"Ed Owens" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>
Tim,
    Thank you for your "factoring" discussion.  While I am opposed to bringing all of the ACM work into the LDUP working group I believe that your suggestion, including sufficient information for publishing access control frameworks but not defining any particular model, is a good compromise that allows LDUP to have some chance of completion without getting bogged down in the seemingly interminable discussion around access control.  I would support changes to the LDUP charter that specified this task.  What I cannot support is the current wording of the charter which moves all of the access control discussion into the LDUP WG which I maintain (with others) will only slow to a crawl any meaningful work on the original goals of LDAP replication.

        Ed Owens

Edward Owens
Principal Consultant
Noetic Solutions LLC
(925)366-1005
[email protected]
http://www.noetic.net
  ----- Original Message ----- 
  From: Timothy Hahn 
  To: Ietf-Ldup@Imc. Org 
  Sent: Monday, November 19, 2001 6:40 AM
  Subject: Re: revised WG charter proposal



  Hello, 

  Excerpt from Proposed WG charter: 

  o LDAPv3 Access Control Issues

    Replication using heterogeneous LDAPv3 servers is dependent on
    resolving LDAPv3 access control issues, which are currently in
    the domain of another Applications Area working group. RFC 2820,
    Access Control Requirements for LDAP, was produced by that working
    group. However, this working group has elected to close prior to
    establishing consensus on other documents, such as an Access Control
    Model specification for LDAPv3. Such documents are necessary for
    LDUP to meet certain replication requirements documented by the
    LDUP WG. Thus, the remaining access control work and the latest
    revision of the access control model Internet Draft produced by
    the originating working group as starting point for continuing
    the work in the LDUP WG.

  My opinion on whether the workgroup should solve the access control model specification is as follows: 

  a) in order for replication to take place and ensure that data replicated in two different server instances is not accessed inappropriately in either one of the server instances, the replication model MUST rely on some statement about access control.  I would expect that these statements would be covered in the "Security Considerations" section of the drafts and RFCs (among other places). 
  b) the past attempts by LDAPext to establish consensus around any particular access control model have not been successful.  Progress has been made, to be sure, but in my opinion, we are not yet near a "final solution" with consensus. 
  c) I do not believe that LDUP requires a FULL access control model specification in order to proceed with a "secure" solution.  By this, I believe that the two problems ARE factorable. 
  d) There are elements of the current access control model specification that could help us "factor" the problems - namely the notion in the current ACM model that each ACI is defined by some OID and the particular ACI(s) that a server supports/uses is held in the root DSE. 

  I feel that the LDUP WG SHOULD pursue a specification of how access control "frameworks" are published (without specifying/defining any particular access control model design).  This allows for two (or n) servers to establish what access control models are defined/implemented on any particular server and for those servers to figure out IF they can "agree" on a ACI model to use. 

  With this "framework" agreed upon, LDUP can state in its "security considerations" that for secure environments, replicating servers MUST implement and use "compatible" ACI models - but LDUP need NOT define any particular model be employed.  I believe that this allows the access control to be "factored" from the replication problem. 

  In summary, I feel that LDUP should NOT take on the "whole" access control problem (as is attempted in the current ACM draft from the LDAPext working group).  Rather, LDUP should take on work to define a "framework" in which different ACI models can be defined and published, and then LDUP should state that "compatible" access control models MUST be used for secure replication. 

  Regards,
  Tim Hahn

  Internet: [email protected]
  Internal: Timothy Hahn/Endicott/IBM@IBMUS or IBMUSM00(HAHNT)
  phone: 607.752.6388     tie-line: 8/852.6388
  fax: 607.752.3681
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.