[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
RE: [ldapext] LDAP and subtree specification and subentries
Hello,
thanks for the clarification. One comment:
> > Other general question: Is it allowed to search / to modify
> > objects of DSE-Type subentry (e.g.
> > collective-attribute-subentries) via LDAP?
>
> Yes.
OK - it's allowed. But it's not really possible because
I can't express some attributes, e.g. subtreeSpecification, in LDAP.
You are right: draft-zeilenga-ldap-subentry-03.txt solves
this problem - but only for subtreeSpecification.
I still can't see how to express
the other attributes I usually find in (X.500) subentries, e.g.
- prescriptiveACI for access control subentries
- DIT content rules and structure rules for subschema subentries
- collective attributes for collective attributes subentries
(e.g. collectiveTelephoneNumber (X.520))
The last one seems to be addressed by draft-zeilenga-ldap-collective-06.txt,
but not the other two kinds of subentries.
So it seems that today each X.500 vendor has a vendor-specific (or no) representation
of these subentries when read / modified via LDAP.
Best regards,
Jochen Keutel.
---
Dr. Jochen Keutel
Management Consultancy
Wusterhausener Str. 8
D-15732 Eichwalde
Germany
phone +49 30 678 19189
mobile +49 177 6572720
e-mail jochen@keutel.de
_______________________________________________
Ldapext mailing list
Ldapext@ietf.org
https://www1.ietf.org/mailman/listinfo/ldapext