[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: general comment on <draft-ietf-ldapext-authmeth-02.txt>



On Wed, 22 Jul 1998, Helmut Baumgaertner wrote:
> <HTML>
> What is the relationship between the openGroup profiles (read-only ldap
> server, read-write
> <BR>ldap server ....) and draft-ietf-ldapext-authmeth.
> <BR>In the latter I would expect to find an INFORMATIONAL description of
> authentication and authorization concepts and certainly a detailed specification
> of the protocol to be sent for the different Authentication Methods.
> <BR>However, the right place for a list of features to be supported by
> ldap servers deployed in
> <BR>different scenarios seems to be the profiles, rather than an ldapext
> rfc.
> <BR>In fact the authentication methods, SASL mechanisms and algorithms
> to be supported are listed
> <BR>in the OpenGroup ldap server profiles.
> <BR>&nbsp;
> <BR>&nbsp;
> <BR>&nbsp;
> <BR>&nbsp;</HTML>

LDAP has to at least specify one mandatory to implement authentication
mechanism so that any client/server pair will be capable of interoperable
write access.  The role of profiles is to specify which mechanisms should
be used in which situations.

BTW, using HTML in email is annoying, especially when plain text would
easily suffice.

		- Chris