Comments on ldup-sync-02
John McMeeking <[email protected]> Fri, 6 Jun 2003 15:56:38 -0500
| Newsgroups | gmane.ietf.ldup |
|---|---|
| Message-ID | <OF916BA416.DEC2D528-ON86256D3D.006DED3C-86256D3D.00730CE4@us.ibm.com> |
A few comments on draft-zeilenga-ldup-sync-2.txt: 1.1 Background - para on state information. It might be more correct to state that LDAP Sync does not require the server to maintain state information beyond that already required by the LDAP v3 RFCs. I think information like modifyTimestamp is state information. 2. Elements of the Sync Operation. This section ought to state that implicit tagging is used. 2.1.2 syncCookie (also Security Considerations). Does the mention of a digital signature belong here? I don't see that tampering with a cookie would be any worse than tampering with anything else in the protocol. I don't see how a malformed cookie could give you access to data you aren't authorized to. At worst, it could cause the client to miss changes or get redundant changes. Any result returned should be subject to the server's access control mechanisms. 4.2 Operational Attributes - delete last sentence: "Synchronization of operational attributes is discussed in Section 4.1." John McMeeking