Re: LDAP Requirements comments
"Ed Reed" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
================= Ed Reed Reed-Matthews, Inc. +1 585 624 2402 http://www.Reed-Matthews.COM Note: Area code is 585 >>> "Kurt D. Zeilenga" <[email protected]> 11/21/01 04:47PM >>> ... G9 states two distinct requirements. Should be separated into two. (I note my previously stated opinion that the second G9 requirement is inappropriate and should be stricken). <eer> Agreed. Also, in doing the coverage matrix, the same is true of G8 (each bullet is a separate requirement), M1, M5, and MM5. </eer> M1 g). I suggest "manual request" be an LDAP request. <eer> I'm undecided on that, and believe that the requirement doc should be silent on the implementation method to be proposed. </eer> AM7. and LDAP replication MUST prevent the establishment of a 'blank' (or partially synced) replica from blanking (or partially syncing) other replicas. <eer> That would be an additional requirement, which I would support. </eer> Suggest: AM8. Vendors SHOULD provide tools to audit schema compatibility within a potential replica-group. be replaced with: AM8. Administrative tool creating new replicas SHOULD detect LDAP Replication SHOULD detect schema incompatibilities prior to instantiating a replication agreement. <eer> agree, after some necessary wordsmithing of some unnecessary redundant unnecessary something... SHOULD...SHOULD should be clarified ... </eer> S6/S7: s/privacy/confidentiality/ <eer> Agree - the whole privacy thing scares the willies out of me, and I don't much care what other document/workgroup/whitepaper has defined definitions...the requirements can assert the need to support confidentiality (ie, encryption of data in transit) but not privacy. </eer> Security considerations: As noted in Section 3, interoperability may be impacted when replicating among servers that implement non-standard extensions to basic LDAP semantics. This doesn't grasp the follow extent of the interoperability issue impacting security. And: Since LDAPv3 access control is a set of standards-based extensions LDAPv3 access control is not yet defined. It may never be. Anyways, I suggest replacing the paragraph with: This document includes security requirements (listed in section 4.8 above) for the replication model and protocol. As noted in Section 3, interoperability may be impacted when replicating amount servers which implement different elective features of LDAP. Hence, security (and general interoperability) will be significantly impacted by the degree of consistency with which LDAP implementations support elective features of LDAP. This can be mitigated by requiring each implementation in a replicated environment implement, in a consistent manner, the same set of elective features. <eer> Concur. I'd go a bit further and explicitly warn that LDUP may really screw up data subject to side effects of LDAP operations, perhaps by listening for change and addition events on the server to increment counters or do other things in external data repositories. </eer>