[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: [ldapext] Password Policy OIDs



>>> John McMeeking <jmcmeek@us.ibm.com> 10/26/04 6:57:05 AM >>>
>I haven't looked to see how close the draft is to either the (then)
>Netscape or the Novell implementations, but here what I think:
>
>If the existing OIDs and descriptive names are based on password policy
>implementations that existed prior to this draft, I think the names and
>OIDs should be changed when the draft departs "far enough" from those
>existing implementations. At a minimum, I think the control OIDs ought to
>be different; that would make it possible for a client to determine which
>password policy implementation was supported by a server and act
>accordingly.
The draft probably drifted 'far enough' from both the Novell and Netscape implementations in the -00 version. The concern is probably how far has it drifted (or will it drift) from where it was when other vendors (OpenLDAP, eB2B, and others) started implementing it?

>If the OIDs and descriptive names in question are defined by the draft, I
>think it is reasonable for the draft to continue use those OIDs and names
>when it changes the semantics defined in a previous version. I think
>anyone implementing an Internet Draft is doing so at their own risk. Isn't
>that part of the rationale behind this statement?
>
>Internet-Drafts are draft documents valid for a maximum of six
>months and may be updated, replaced, or obsoleted by other documents
>at any time. It is inappropriate to use Internet-Drafts as
>reference material or to cite them other than as "work in progress."
Yes, you're exactly right. There is technically no problem with us retaining the OIDs and wildly changing semantics or definitions. Early adopters should have used their own OIDs (and descriptors) to begin with. My guess (I have no evidence) is that early implementors have used the specified OIDs and names, and I want to make life easy on them as well make the I-D as easy to update.

Jim
_______________________________________________
Ldapext mailing list
Ldapext@ietf.org
https://www1.ietf.org/mailman/listinfo/ldapext