Re: PCLS when? [was: Re: Approved: draft-ietf-policy-core-schema-16.txt]
"Joel M. Halpern" <[email protected]> Wed, 14 May 2003 10:15:56 -0400
| Newsgroups | gmane.ietf.policy |
|---|---|
| Message-ID | <[email protected]> |
At the moment I am still operating on the assumption that the IESG will get the user schema document unstuck. We went through a lot of discussion in earlier reviews to arrive at the agreement that we would use that document as the basis for those aspects of our LDAP work. I am loath to attempt to change that conclusion unless the AD informs us that the zeilenga document will not be going forward. Yours, Joel M. Halpern At 07:57 AM 5/14/2003 -0500, Larry S. Bartz wrote: >Now it has been *six* months since the PCLS (Policy Core LDAP Schema) >draft entered the RFC Editor's Queue. When will the RFC be published? > >I haven't seen a convincing argument for retaining PCLS's dependency >upon draft-zeilenga-ldap-user-schema. > >Larry > > >Larry S. Bartz wrote, On 05/06/03 11:11: >>Mircea, all, >>Reference to X.520 (for which there is already a normative reference >>in the draft) is the *only* normative reference which is necessary to >>cover the three matching rules. >>X.520 defines booleanMatch, octetStringOrderingMatch, and >>integerOrderingMatch. >>Where draft-zeilenga-ldap-user-schema speaks of these three matching >>rules, it does little more than re-state X.520. There is no doubt >>about consensus regarding the origins and semantics of booleanMatch, >>octetStringOrderingMatch, and integerOrderingMatch. >>To remove the normative reference to draft-zeilenga-ldap-user-schema >>is simply to remove a redundancy. Removing the normative reference to >>draft-zeilenga-ldap-user-schema does not leave draft-ietf-policy-core >>-schema-16 without a normative reference for the three matching rules. >>Larry >> >>Pana, Mircea wrote, On 05/06/03 10:36: >> >>>Larry, >>> >>>I don't have a strong opinion about the booleanMatch and wrt. the >>>octetStringOrderingMatch I don't even see where it might be necessary. >>>However, the integerOrderingMatch might be critical to some policy >>>aplications. Therefore, as much as I'd like to see this ID progress to RFC, >>>I believe that the removal of the normative reference is detrimental to this >>>document. >>> >>>I know that some Directory vendors already implement these matching rules. >>>The problem is that, without a normative document, each vendor might >>>implement different behavior for the same rule... >>> >>>Mircea. >>> >>> >>>-----Original Message----- >>>From: Larry S. Bartz [mailto:[email protected]] >>>Sent: Monday, May 05, 2003 2:33 PM >>>To: Wijnen, Bert (Bert) >>>Cc: RFC Editor; Randy Bush; [email protected]; Joel M. Halpern; Ed >>>Ellesson >>>Subject: Re: [Policy] Approved: draft-ietf-policy-core-schema-16.txt >>> >>> >>>I raised the following points last week, but didn't get a rise >>>out of anybody... >>> >>>draft-ietf-policy-core-schema-16 uses three matching rules which >>>haven't been explicitly defined as standard LDAP matching rules. They >>>are booleanMatch, integerOrderingMatch, and octetStringOrderingMatch. >>>These matching rules are the subject of draft-ietf-policy-core-schema- >>>16's dependence upon draft-zeilenga-ldap-user-schema. >>> >>>What does "adapted for use in LDAP" mean for those matching rules? >>>According to draft-zeilenga-ldap-user-schema, the "adaptation" is >>>little more than a restatement of the X.520 definitions. Obviously, >>>X.520 provides the consensus-supported definitions for booleanMatch, >>>integerOrderingMatch, and octetStringOrderingMatch. >>> >>>Some LDAP-conformant server implementations already support >>>booleanMatch, integerOrderingMatch, and octetStringOrderingMatch in >>>conformance with their X.520 definitions. Does it matter that these >>>X.520-defined matching rules are not yet defined in an LDAP-specific >>>RFC? The server doesn't care. The schema doesn't care. The applications >>>which use the server and the schema don't care, either. >>> >>>Rough consensus and working code, right? How could consensus get any >>>better for these three matching rules than it already is? I realize that >>>Kurt, the ldapbis WG, and the IETF are working very hard to make LDAP >>>more concise, precise, and complete. This is Good Work. But in the case >>>of draft-ietf-policy-core-schema-16 and these three matching rules, if >>>the subject of the normative reference at issue here isn't immediately >>>forthcoming, there really isn't a good reason for draft-ietf-policy- >>>core-schema-16 to wait any longer. >>> >>>If draft-zeilenga-ldap-user-schema still has serious issues, why not >>>defer to pragmatism, drop the reference, and move on? >>> >>>Larry >>> >>> >>>Wijnen, Bert (Bert) wrote, On 05/05/03 12:59: >>> >>>>RFC-Editor (and policy FW WG) >>>> >>>>As far as my current understanding of the issues, it is NOT >>>>acceptable to remove this normative reference. >>>> >>>>I am working in the IESG to try and get that normative document >>>>approved. But there are still serious issues with it, so things >>>>are not going smooth/fast. >>>> >>>>Thanks, >>>>Bert >>>> >>>> >>>>>-----Original Message----- >>>>>From: RFC Editor [mailto:[email protected]] >>>>>Sent: maandag 5 mei 2003 19:35 >>>>>To: Bert Wijnen; Randy Bush >>>>>Cc: [email protected]; Joel M. Halpern; Ed Ellesson; RFC Editor; >>>>>[email protected] >>>>>Subject: Re: [Policy] Approved: draft-ietf-policy-core-schema-16.txt >>>>> >>>>> >>>>>Bert and Randy, >>>>> >>>>>Could you please let us know if removal of the normative reference is >>>>>an acceptable resolution to unblocking >>>>><draft-ietf-policy-core-schema-16.txt>? >>>>>Thanks, >>>>> >>>>>RFC Editor >>>>> >>>>> >>>>>On Mon, Apr 21, 2003 at 09:38:43AM -0500, Larry S. Bartz wrote: >>>>> >>>>> >>>>>>Larry S. Bartz wrote, On 04/10/03 07:26: >>>>>> >>>>>> >>>>>>>It has been more than five months since we were advised that the >>>>>>>PCLS was approved by the IESG. Why hasn't the RFC been published? >>> > >