[Date Prev][Date Next] [Chronological] [Thread] [Top]

Document Action: LDAP Control Extension for Simple Paged Results Manipulation to Informational




The IESG has approved the Internet-Draft 'LDAP Control Extension for
Simple Paged Results Manipulation'
<draft-ietf-asid-ldapv3-simplepaged-03.txt> as an Informational RFC.
This document is the product of the LDAP Extension Working Group.

The IESG contact persons are Keith Moore and Patrik Faltstrom.


Note to the RFC-Editor:

The IESG requests the RFC Editor to replace "6. Security
Considerations" with the following:

6. Security Considerations

Server implementors should consider the resources used when clients
send searches with the simple paged control, to ensure that a client's
misuse of this control does not lock out other legitimate operations.

Servers implementations may enforce an overriding sizelimit, to prevent
the retrieval of large portions of a publically-accessible directory.

Clients can, using this control, determine how many entries match a
particular filter, before the entries are returned to the client.  This
may require special processing in servers which perform access control
checks on entries to determine whether the existence of the entry can
be disclosed to the client.