Re: Service location vs. careless privacy infringement

Erik Guttman <[email protected]> Thu, 2 Jul 1998 10:23:54 -0700
Newsgroups gmane.ietf.lsd
Message-ID <199807021725.TAA06367@ffm-1-home>
> On Thursday, 2 Jul 1998, Hallvard B Furuseth writes:
> >Has anything been done to prevent service location from magnifying the
> >problem of servers that carelessly ignore privacy protection?  This
> >needs to be addressed, but seems woefully absent from the documents I've
> >plowed through so far.
> >
> Date: Thu, 2 Jul 1998 17:01:27 +0000
> From: Peter Gietz <[email protected]>
>
> But to cut off server location because illegal data could be retrieved
> would be the same as to cut HTTP because illegal pictures can be
> transmitted via it.
>
> Peter
>

The service location protocol work has always considered that there
is no great value in security by obscurity.  The service location
protocol makes the location and configuration information of services
available to anyone, leaving access control to the client-server
protocol itself.

SLP allows for either decentralized discovery (ie. with no other
infrastructure); it also can be used to gather service information
dynamically from services to place them in centralized network
information directories.  In both cases the attempt is to make the
information as accurate, current and available as possible.

It is unreasonable to assume that privacy, access control and
authorization of network resources will be handled at multiple
levels of the network infrastructure.  (I consider Service Location
to be part of the infrastructure since it is a basic service offered
for reducing administration requirements of networks.)  Rather,
AAA should be done by the services which have the sensitive information.

An interesing question is - how do you centralize the authentication,
access control, authorization, etc. so that each service doesn't have
to go its own way.  This is precisely where directories are essential,
I believe.  So I'm agreeing with Thomas Lenggenhager:

> Date: Thu, 02 Jul 1998 15:07:57 +0200
> From: Thomas Lenggenhager <[email protected]>
> The right way is to improve the LDAP servers deploied with appropriate
> configuration methods to distinguish between local and non local users.


-----------------------------------------------------------------------
Erik Guttman                        http://www.neato.org/~femur/eg.html
Sun Microsystems                                   [email protected]
SMCC Advanced Network Development                      +49 7263 911 701