LDAP ACM in security considerations (RE: I-D ACTION:draft-ietf-ldup-replica-req-11.txt)

"Kurt D. Zeilenga" <[email protected]>
Newsgroups gmane.ietf.ldup
Message-ID <[email protected]>
At 02:33 PM 2002-03-06, Chris Apple wrote:
>As co-chair, I don't want to *prematurely* put language in a
>requirements
>document attempting to constrain that path only to have it:

This is actually what is being done by placing a reference to
RFC 2820.  The statement presumed that there eventually would
be a technical specification meeting RFC 2820 requirements which
LDAP implementations could support just as previous revisions
had presumed LDAPext would have produced an standard track
LDAP ACM.

A statement stating that a standard LDAP access control
model is needed, without stating any requirements upon
that standard LDAP access control model, would be less
premature.

Something like:
  This document includes security requirements (listed in
  section 4.8 above) for the replication model and protocol. As
  noted in Section 3, interoperability may be impacted when
  replicating among servers that implement non-standard
  extensions to basic LDAP semantics. Security- related and
  general LDAP interoperability will be significantly impacted
  by the degree of consistency with which implementations
  a future standard LDAP access control model.

This statement should not be limited our path.  That is, the
statement is valid whether or not we take on this "future
standard LDAP access control model" or not.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.