Comments on ldup-sync-02

John McMeeking <[email protected]> Fri, 6 Jun 2003 15:56:38 -0500
Newsgroups gmane.ietf.ldup
Message-ID <OF916BA416.DEC2D528-ON86256D3D.006DED3C-86256D3D.00730CE4@us.ibm.com>




A few comments on draft-zeilenga-ldup-sync-2.txt:

1.1 Background - para on state information.  It might be more correct to
state that LDAP Sync does not require the server to maintain state
information beyond that already required by the LDAP v3 RFCs.  I think
information like modifyTimestamp is state information.

2.  Elements of the Sync Operation.  This section ought to state that
implicit tagging is used.

2.1.2 syncCookie (also Security Considerations).  Does the mention of a
digital signature belong here?  I don't see that tampering with a cookie
would be any worse than tampering with anything else in the protocol.  I
don't see how a malformed cookie could give you access to data you aren't
authorized to.  At worst, it could cause the client to miss changes or get
redundant changes. Any result returned should be subject to the server's
access control mechanisms.

4.2 Operational Attributes - delete last sentence: "Synchronization of
operational attributes is discussed in Section 4.1."


John  McMeeking