[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: root dse search



"Ramsay, Ron" wrote:
> 
> I think that the 4.5.1 statement regarding the return of operational
> attributes was itself overridden in the case of the root DSE. For example,
> namingContexts is an operational attribute but (is this Netscape's doing)
> clients expect it to be returned. I changed my implementation for
> interoperability. I think Mark Wahl has written on the LDAPext list that
> operational attributes in the root DSE are treated as user attributes.

I think some implementations have done one thing (treat the rootDSE
attributes as special) and some have do another (treat them like regular
operational attributes).  The correct answer is in the eye of the
beholder.  It seems more convenient to me to return the rootDSE
attributes even when the client does not request them, but I see
no text in 2251 or 2252 that explicitly supports that point of view.

For better or worse, the Netscape server (now iPlanet) has always
returned the root DSE attributes without the client requesting them by
name.  I am sure that means there are a lot of clients out there that DO
NOT request them by name.  My practical side says, let's not break those
clients.  But I can't speak to the intent of the authors of 2251 or
2252.

-Mark Smith
 Netscape