Re: Object Class Violation

Mike Jackson <[email protected]> Thu, 04 Aug 2005 18:31:07 +0300
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Dieter Kluenter wrote:
> 
> RH Directory Server is the old Netscape i-Planet, which in fact
> derived from U-MICH, same as Sun One and OpenLDAP.
> While OpenLDAP has gone a long path of further development, i-Planet
> and Sun One remained in a somewhat infant state, and both are not
> fully LDAPv3 compliant.


Dieter, this is pure flamebait. Too bad we're not on Slashdot :-) But, 
we are all entitled to our own opinions.

Tim Howes started and led the LDAP project at U-MICH, creating LDAPv1 - 
a tcp proxy to X.500 servers. He standardized and implemented LDAPv2 
while at U-MICH. He got his PhD and was hired as vice president of 
engineering at Netscape, where he standardized LDAPv3 (RFC 2251) 
together with his Mark Wahl (Critical Angle) and Steve Kille (Isode, an 
X.500 software company). He subsequently led the development of the 
first LDAPv3 server in the world.

Netscape implemented the first LDAPv3 (RFC 2251) compliant server the 
world saw, as an internal project, and made the first public release in 
1997, which is why the first public version was already at 3.x. It has 
been profesionally designed, system engineered, tested, and supported at 
large customer installations all over the world for more than 8 years, 
adding new features all the way.

In contrast, OpenLDAP started in 1999, by forking the U-Mich LDAPv2 
codebase. In 2000, OpenLDAP could handle 5 queries per second. It wasn't 
until the Symas Corporation came along and helped them out that OpenLDAP 
started to become even useful as a prototyping tool.

OpenLDAP didn't release a stable version of an LDAPv3 server until mid 
2002, 5 years after Netscape had released a much more advanced server.

OpenLDAP project generally told users to piss off when they requested 
things like cn=config, in-tree access control, multi-master replication, 
etc. Now that Fedora is open-source, they are starting to feel the need 
to compete or something, and are _finally_ starting to consider and 
release some new features.

I am responsible for architecting and supporting ~9k LDAP servers around 
the world, in the telecoms sector, and I would not deploy OpenLDAP into 
that environment even if you threatened to chop my right hand off. I 
can't just go to 9k machines and deploy a new version every 2 months 
because the OL developers refuse to support anything which is a year or 
more old, what they call "ancient".

In an infant state, indeed...

--
mike