Re: LDAP Requirements comments
"Kurt D. Zeilenga" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
At 05:59 PM 2001-11-21, Ed Reed wrote: >>> These models [4 and 5] violate a directory's security policies. >>How? An "unregistered" replica can enforce security policies >>just as well as a "registered" replica. >But, they can also choose not to, and if the data owner doesn't know >who is replicating the data, they're certainly not likely to rely on the >unknown recipients to be "honor bound" to handle the data >appropriately. I'd say "registered" replica are no more "honor bound" than "unregistered" replica. I believe model 4 and 5 should be excluded, not for security reasons as the requirement I-D implies, but because they are adequately addressed by other protocols and mechanisms.