Re: LDAP Requirements comments

"Ed Reed" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>


=================
Ed Reed
Reed-Matthews, Inc.
+1 585 624 2402
http://www.Reed-Matthews.COM
Note:  Area code is 585

>>> "Kurt D. Zeilenga" <[email protected]> 11/21/01 04:47PM >>>
...

  Models 4 and 5 involve unregistered replicas that "pull"
  updates from another directory server without that
  server's knowledge.

Assuming LDAP as the access protocol, an unregistered
replica cannot "pull" updates from a server without that
server's knowledge. 

<eer>
A couple of points - 

1) if it were so easy for a server to know that an unregistered
replica is pulling updates from it, then data mining for
spam addresses, etc. would be easy. Spam and web-crawlers
have demonstrated that it's not.

2) I don't expect LDUP to support these models at all, and look to
things like LCUP as potential solutions.  LDUP depends on knowing
that updates have reached all (registered) replicas in order to
govern each server's own change log truncation / garbage collection.

</eer>

  These models violate a directory's security policies.

How?  An "unregistered" replica can enforce security policies
just as well as a "registered" replica.

<eer>
 
But, they can also choose not to, and if the data owner doesn't know
who is replicating the data, they're certainly not likely to rely on the
unknown recipients to be "honor bound" to handle the data
appropriately.

No, the very notion that ACM policy would allow an unknown
and unregistered DSA to receive sensitive data subject to 
the ACM policy seems outlandish.

At the very least, sensitive data can only be shared with those
who will be accountable for its protection, and who will protect
it according to the data policies established by the data owners.

See innumerable rants about personal privacy for corroborating
arguments.

</eer>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.