Re: Question re: requirement S3
"Ed Reed" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
Yeah, okay - I can live with the ftp example, and I do keep forgetting about how running things behind a datacenter firewall (even on a blade server cluster, for that matter) could benefit from such a thing. I'll relent. I disagree, though, that it should be considered useful when setting up a new replica...but then again, I've got nothing against requiring a DSA to go off-server to get authentication credentials/certificates for authenttication, and I know not everyone does... Sigh - I will point out that Anonymous FTP has been a royal pain in the administration of may sites - not only because it's a denial of service attack waiting to happen (if your firewalls slip), but because of the "innovative" ways of using it (IRC) that plague unspecting administrators. Ready for LDUP to fill the same role? Ed >>> Richard Huber <[email protected]> 02/28/02 10:41AM >>> This is my recollection of some of the discussion we had among the authors when we added S3. The other authors can chip in if they remember things differently. First, S3 is not intended to require that servers always accept anonymous replication requests. It just says that the protocol needs to support such requests if a given pair of servers is configured to use them. An analogous situation is FTP, where anonymous FTP is supported in the protocol but is turned of on many FTP servers. So when you say "of course, there's nothing to prevent someone from trying to initiate one" it seems that we may already be in agreement. As for the circumstances where it might be useful to have anonymous replication, a set of replicating directory servers on a private net behind a firewall that only lets through LDAP requests would not need authentication among the replicating servers; security in this case has been provided by means outside of LDAP/LDUP. These are the same sorts of situations where the confidentiality features might not be needed. And there may be some situations in setting up a new replica where it is useful to have anonymous replication (see Section 5.1 and 5.1.1 of the MRM draft). There are certainly many situations where anonymous replication is a very BAD idea. It should be disabled in such situations. But it should not be absolutely forbidden in all situations. Rick Huber Ed Reed wrote: > Uppili and I are working on updating the Architecture document (!) and have a question about requirement S3 - The protocol MUST also support the initialization of anonymous replication sessions. > > Politely, are you sure? We would much rather strictly prohibit acceptance of LDUP replication sessions over unauthenticated anonymous connections. (of course, there's nothing to prevent someone from trying to initiate one, I suppose, but there certainly ought not be any requirement to accept one). > > Why is there any reason for any server to ever accept anonymous assertion of replica changes it is supposed to send or receive? > > Your clarification will be greatly appreciated. In the meantime, the architecture document will continue to require authentication for all replication sessions. > > Ed and Uppili > > ================= > Ed Reed > Reed-Matthews, Inc. > +1 585 624 2402 > http://www.Reed-Matthews.COM > Note: Area code is 585