Re: LDAP Requirements comments
"Ed Reed" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
================= Ed Reed Reed-Matthews, Inc. +1 585 624 2402 http://www.Reed-Matthews.COM Note: Area code is 585 >>> "Kurt D. Zeilenga" <[email protected]> 11/21/01 04:47PM >>> ... Models 4 and 5 involve unregistered replicas that "pull" updates from another directory server without that server's knowledge. Assuming LDAP as the access protocol, an unregistered replica cannot "pull" updates from a server without that server's knowledge. <eer> A couple of points - 1) if it were so easy for a server to know that an unregistered replica is pulling updates from it, then data mining for spam addresses, etc. would be easy. Spam and web-crawlers have demonstrated that it's not. 2) I don't expect LDUP to support these models at all, and look to things like LCUP as potential solutions. LDUP depends on knowing that updates have reached all (registered) replicas in order to govern each server's own change log truncation / garbage collection. </eer> These models violate a directory's security policies. How? An "unregistered" replica can enforce security policies just as well as a "registered" replica. <eer> But, they can also choose not to, and if the data owner doesn't know who is replicating the data, they're certainly not likely to rely on the unknown recipients to be "honor bound" to handle the data appropriately. No, the very notion that ACM policy would allow an unknown and unregistered DSA to receive sensitive data subject to the ACM policy seems outlandish. At the very least, sensitive data can only be shared with those who will be accountable for its protection, and who will protect it according to the data policies established by the data owners. See innumerable rants about personal privacy for corroborating arguments. </eer>