LDAP ACM in security considerations (RE: I-D ACTION:draft-ietf-ldup-replica-req-11.txt)
"Kurt D. Zeilenga" <[email protected]>
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <[email protected]> |
At 02:33 PM 2002-03-06, Chris Apple wrote: >As co-chair, I don't want to *prematurely* put language in a >requirements >document attempting to constrain that path only to have it: This is actually what is being done by placing a reference to RFC 2820. The statement presumed that there eventually would be a technical specification meeting RFC 2820 requirements which LDAP implementations could support just as previous revisions had presumed LDAPext would have produced an standard track LDAP ACM. A statement stating that a standard LDAP access control model is needed, without stating any requirements upon that standard LDAP access control model, would be less premature. Something like: This document includes security requirements (listed in section 4.8 above) for the replication model and protocol. As noted in Section 3, interoperability may be impacted when replicating among servers that implement non-standard extensions to basic LDAP semantics. Security- related and general LDAP interoperability will be significantly impacted by the degree of consistency with which implementations a future standard LDAP access control model. This statement should not be limited our path. That is, the statement is valid whether or not we take on this "future standard LDAP access control model" or not.