RE: A philosophical question about large directory structures
Erik Skovgaard <[email protected]> Thu, 22 Jul 1999 09:31:07 -0700
| Newsgroups | gmane.ietf.lsd |
|---|---|
| Message-ID | <[email protected]> |
Alexis, I still feel very strongly that the dc= naming is a bad thing. Look at the number of entries immediately under dc=com! The correct thing to do is to reduce the search set quickly (CS 101 as I recall) and the best way we currently have is to use the division by country. In practice, that is what is done many places around the world. Certainly, we can agree that not all directories will be interconnected, but to make the assumption that none of them will, is plainly a bad assumption. I think PKI will drive a lot of the interconnection or at least coordination. Cheers, ....Erik. ------------------------------------ Erik Skovgaard GeoTrain Corp. Enterprise Directory Planning Services http://www.geotrain.com At 16:37 99/06/28 -0400, Alexis Bor wrote: >Tim, >I agree with you that domain names are what people are good at guessing >these days. I think that we learned that lesson at least twice, once with >email and once with the web. > >I have been preaching the idea of the DN as just a pointer to an entry since >the early 90s and have always hid them from all of my applications. I'm >glad that others are seeing the value in that, but it has been a long road. > >Naming has always been an ugly thing and it has caused lots of grief to all >of us in the directory space, as well as others. Everyone seems to take >names very seriously - and understandably so. The real question is how to >do we get past that. I think that dc naming gets us part of the way there. >What we need is a mechanism where if we don't know the dc, to go out and >find it - and hopefully we can do that with protocol most of the time. > >You made an interesting comment early on in this thread that 4 years ago you >realized that directories wouldn't be all connected and that it was probably >a bad thing if they were. I tend to disagree with that. I think that you >were right 4 years ago that the current method of doing it was not workable >for both social and technical reasons. However, that doesn't remove the >need for doing it some day. If you think of DNS as a form of directory, >then it is possible and is useful. I think that there are many applications >that are currently disabled because they can't get to information that could >be stored in directories. > >We are on the verge of having directories deployed in almost every company >with an IT department on the planet, many of them will have multiple >directories from multiple vendors. At that point, it will be clear that we >need to quickly figure out how to do it, and the rewards will be great. >Just think back of what it was like to maintain HOSTS tables for every >system running IP, and that wasn't very long ago. I think that twenty years >from now, we'll be talking about the good 'ol days when business to business >communication that uses directories was just a dream that many of us were >saying would never happen. And noone will believe that they made routers >and hubs that didn't use DEN... > >-- Alexis > > >Alexis Bor >Directory Works, Inc. >P.O. Box 470276 >Celebration, FL 34747-0276 >407-566-9250 >407-566-9251 (FAX) >[email protected] >http://www.directoryworks.com > > >> -----Original Message----- >> From: [email protected] >> [mailto:[email protected]]On Behalf Of >> Tim Howes >> Sent: Wednesday, June 23, 1999 6:58 PM >> To: Erik Skovgaard >> Cc: Thomas Lenggenhager; [email protected] >> Subject: Re: A philosophical question about large directory structures >> >> >> Just an opinion, but I don't think anybody wants to >> guess at distinguished names. I actually think it's >> likely to be significantly less effective than trying >> to guess domain names, which people seem to be guessing >> or otherwise figuring out today without too much >> trouble. And I don't think any respectable user agents >> will support guessing except possibly as some last >> resort mode of operation. We've seen directory clients >> moving more and more toward hiding DNs from users, and >> I think that's a very good thing and one we're likely >> to see increasingly. -- Tim >> >> Erik Skovgaard wrote: >> > >> > Thomas, >> > >> > I agree that namespaces have to be unique, but I *also* >> believe they should >> > make sense to users. Granted, *some* host names are >> user-friendly, but >> > many are not. >> > >> > In the specific example you mention, I would suggest that {o=Sun >> > Microsystems, c=ch} is a reasonable and guessable >> namespace. I would not >> > venture to guess what your hostname is. >> > >> > Cheers, ....Erik. >> > >> > ----------------------------------- >> > Erik Skovgaard >> > GeoTrain Corp. >> > Enterprise Directory Engineering >> > http://www.geotrain.com >> > >> > At 23:41 99/06/23 +0200, Thomas Lenggenhager wrote: >> > >On Wednesday, 23 Jun 1999, Erik Skovgaard writes: >> > >> The DC namespace is poorly suited for the Directory >> since the Internet host >> > >> names are not all guessable. For instance, if I were to >> look up Canadian >> > >> Airlines, I would have to *know* that the hostname is >> 'cdnair.com'. >> > > >> > >We are going a bit off track with these messages about namespace. >> > > >> > >The namespace should mainly be unique. That would be >> provided by DC. >> > >Finding something should not be tried to achieve by >> guessing the right >> > >name, but by searching for it (index/directory). >> > > >> > >> Since the Directory name registration is closely tied to >> the legal names of >> > >> companies in most countries, I think that makes for a >> much better choice. >> > >> I would rather find Canadian Airlines as {o=Canadian >> Airlines, c=ca} than >> > >> the somewhat cryptic {dc=cdnair, dc=com}. >> > > >> > >And how about the official name of Canadian Airlines in >> French and the >> > >DN you proposed? >> > > >> > >What is the official name of a company? >> > > Acme or Acme Inc. or Acme, Inc. >> > > >> > >Just as an example of quite ugly and non-guessable names, >> the official >> > >name of Sun in Switzerland: >> > > Sun Microsystems (Schweiz) AG >> > > >> > >Thomas >> > > >> > > >> >> -- >> Tim Howes >> Vice President, Technology >> Office of the CTO >> America Online, Inc. >> > > > >Attachment Converted: "d:\Program Files\Eudora\Attach\Alexis Bor (E-mail)3.vcf" >