RE: I-D ACTION:draft-ietf-ldup-replica-req-11.txt

"Kurt D. Zeilenga" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>
At 06:41 AM 2002-03-06, Chris Apple wrote:
>I have read RFC 2820 5 times this morning and cannot find a statement
>in it that supports your claim.

Much like the LDUP Requirements I-D, RFC 2820 is NOT a protocol
technical specification.  It outlines design requirements
which engineers of a technical specification should consider.

The statement "LDAP implementations support the access
control requirements [RFC2820]" makes no sense as
RFC 2820 makes no requirements upon LDAP implementations.

Now, the statement could be rewritten:
  Security- related and general LDAP interoperability will
  be significantly impacted by the degree of consistency
  with which LDAP implementations support a future Standard
  Track technical specification meeting Access Control
  Requirements for LDAP [RFC2820]. 


Kurt



>Consider the document's abstract:
>
>Abstract
>
>   This document describes the fundamental requirements of an access
>   control list (ACL) model for the Lightweight Directory Application
>   Protocol (LDAP) directory service.  It is intended to be a gathering
>   place for access control requirements needed to provide authorized
>   access to and interoperability between directories.
>
>Given that summary of RFC 2820, I don't follow your claim that
>the text from the security considerations section makes no sense.
>
>Chris Apple
>
>[email protected]
>
>-----Original Message-----
>From: [email protected] [mailto:[email protected]]
>On Behalf Of Kurt D. Zeilenga
>Sent: Tuesday, March 05, 2002 11:29 PM
>To: [email protected]
>Subject: Re: I-D ACTION:draft-ietf-ldup-replica-req-11.txt
>
>
>
>In reviewing this latest revision to see if the changes
>reflect WG input, I find that the following new text in
>the the Security Consideration section makes no sense.
>
>  Security- related and general LDAP interoperability will
>  be significantly impacted by the degree of consistency
>  with which LDAP implementations support the access
>  control requirements [RFC2820]. 
>
>RFC 2820 does not provide a technical specification or otherwise make
>requirements upon LDAP implementations. It places requirements upon
>LDAPext engineering work. That is, RFC 2820 has itself zero impact on
>LDAP interoperability.
>
>Kurt
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.