Re: LDAP Requirements comments

"Ed Reed" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>


=================
Ed Reed
Reed-Matthews, Inc.
+1 585 624 2402
http://www.Reed-Matthews.COM
Note:  Area code is 585

>>> "Kurt D. Zeilenga" <[email protected]> 11/21/01 04:47PM >>>
...

G9 states two distinct requirements.  Should be separated into
two.  (I note my previously stated opinion that the second G9
requirement is inappropriate and should be stricken).

<eer> 
Agreed.  Also, in doing the coverage matrix, the same is true of
G8 (each bullet is a separate requirement), M1, M5, and MM5.

</eer>

M1 g).  I suggest "manual request" be an LDAP request.

<eer>
I'm undecided on that, and believe that the requirement doc
should be silent on the implementation method to be proposed.
</eer>

AM7. and LDAP replication MUST prevent the establishment of
a 'blank' (or partially synced) replica from blanking (or
partially syncing) other replicas.

<eer>
That would be an additional requirement, which I would support.
</eer>

Suggest:
  AM8. Vendors SHOULD provide tools to audit schema compatibility
  within a potential replica-group.
be replaced with:
  AM8. Administrative tool creating new replicas SHOULD detect
  LDAP Replication SHOULD detect schema incompatibilities prior
  to instantiating a replication agreement.

<eer> agree, after some necessary wordsmithing of some
unnecessary redundant unnecessary something...
SHOULD...SHOULD should be clarified ...
</eer>



S6/S7:  s/privacy/confidentiality/

<eer>
Agree - the whole privacy thing scares the willies out of me, and
I don't much care what other document/workgroup/whitepaper
has defined definitions...the requirements can assert the
need to support confidentiality (ie, encryption of data in transit)
but not privacy.
</eer>

Security considerations:
  As noted in Section 3, interoperability may be impacted when
  replicating among servers that implement non-standard extensions
  to basic LDAP semantics. 
This doesn't grasp the follow extent of the interoperability issue
impacting security.   And:
   Since LDAPv3 access control is a set of standards-based
   extensions
LDAPv3 access control is not yet defined.  It may never be.

Anyways, I suggest replacing the paragraph with:
  This document includes security requirements (listed in
  section 4.8 above) for the replication model and protocol.
  As noted in Section 3, interoperability may be impacted when
  replicating amount servers which implement different elective
  features of LDAP.  Hence, security (and general interoperability)
  will be significantly impacted by the degree of consistency
  with which LDAP implementations support elective features of
  LDAP.  This can be mitigated by requiring each implementation
  in a replicated environment implement, in a consistent manner,
  the same set of elective features.

<eer>
Concur.  I'd go a bit further and explicitly warn that LDUP may
really screw up data subject to side effects of LDAP operations,
perhaps by listening for change and addition events on the
server to increment counters or do other things in external data
repositories.
</eer>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.