Re: A philosophical question about large directory structures

[email protected] (Mark C Smith) Thu, 24 Jun 1999 16:46:46 -0400
Newsgroups gmane.ietf.lsd
Organization Netscape Communications
Message-ID <[email protected]>
Erik Skovgaard wrote:
> ...
> But we are talking about limiting the search here.  If the DIT is divided
> into countries, we at least have a good start.

Okay, I agree.  But looking at the problem another way, I don't see how
we can possible get everyone to go through another registration process
in order to run a directory service.  Most Internet centric people will
say "But I already have a domain name.  What more do I need?"  I think
it is foolish to think we can create a registration process for
directory content that has fewer problems than DNS does (forgetting
about cost).  It will never get off the ground -- at least not in the
U.S.  This is all my opinion of course but history so far is on my side.

> ...
> >LDAP is sufficient for 2) but not for 1) by itself.  Actually, the
> >problem is not with LDAP but, as many others here have pointed out, it
> >is with registering directory services and building a global service.
> >There is no incentive for anyone to do it... and not enough incentive
> >for everyone to play nice together to build it.
> 
> Exactly!  That has always been our problem.  However, with PKI as the
> incentive many countries are actually setting up a name registration
> authority.

In the U.S., there is no central PKI registration authority as far as I
know.  In many countries there is no PKI deployed at all probably.  I'd
love for a global PKI to be deployed, but I think the current technology
is neither sufficient nor mature enough.  I think the wait will be long
and the costs high.  I hope I am wrong about that as Netscape is a PKI
vendor.

I don't really see where this thread is headed, so I am going to bow out
for now.

-- 
Mark Smith
Directory Architect / Sun-Netscape Alliance
My words are my own, not my employer's.  Got LDAP?