[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: [ldap] Re: Version of Netscape Directory Service portocol



Please excuse a potentially ignorant question, but will this also apply to
ACI (which I seem to remember are defined as operational attributes) as
well?

I would not recommend support for returning ACI.

Regards,
Sandi Miklos

-----Original Message-----
From: Ramsay, Ron [mailto:Ron.Ramsay@ca.com]
Sent: Friday, May 19, 2000 1:05 AM
To: Kurt D. Zeilenga; Mark Wahl
Cc: ietf-ldapext@netscape.com
Subject: RE: [ldap] Re: Version of Netscape Directory Service portocol


I agree that RFC 2251/2252 need clarification on this point.

-----Original Message-----
From: Kurt D. Zeilenga [mailto:Kurt@OpenLDAP.org]
Sent: Friday, 19 May 2000 5:25
To: Mark Wahl
Cc: Roger Harrison; ietf-ldapext@netscape.com; sknatarajan@novell.com;
John Aurich
Subject: Re: [ldap] Re: Version of Netscape Directory Service portocol


The answer was in X.511(97) section 7.6:
  If the allUserAttributes option is selected,
  then information is requested about all user attributes in the entry.

This option is equivalent to an empty or "*" search list in LDAPv3.
Hence, I believe the compliant behavior is to only return
operational attributes when requested.

Note: X.511 refers to an allOperationalAttributes option.
LDAPv3 does not have such, but could... it's been suggested
before that "+" be used to indicate allOperationalAttributes
(the OpenLDAP server supports this).

Regardless of whether you agree with my logic here or not, I
hope you would agree that RFC 2251 needs to be clarified in
this area (and other areas).  I hope we can initiate LDAPv3 soon.

Kurt



****************************************************************************
*
This confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.
****************************************************************************
**