[Date Prev][Date Next]
Re: Test operations
Morteza Ansari wrote:
I definitely second this, SunDS also supports this control (I am not
sure if the two implementations are 100% compatible though).
Converging on this would make app's developers job easier.
Interesting, considering that this draft hasn't progressed very far and
has no OIDs assigned. How exactly do you expect anyone to write a
compatible implementation? And of course "It is inappropriate to use
Internet-Drafts as reference material or to cite them other than as
"work in progress.""
The old draft mentioned support for X.500 access controls, but the
latest draft (rev 06, 14 July 2000) doesn't mention it any more. All of
which may be academic since the LDAPext working group shut down and this
draft expired in January 2001.
at least current, and the X.500 models it describes have already been
widely implemented by X.500 vendors. In this respect, it doesn't have
the shortcomings of the LDAPext model (which among other things doesn't
allow for value-specific rights).
Before going off and implementing an expired draft, it would be nice to
understand why the model never made it beyond draft status. Surely it
does not reflect well on the described model for it to have been
abandoned by the authors. Nor would it reflect well on us to claim
support for what can only be considered an incomplete specification.
David Boreham wrote:
Now I'm looking to write an extended operation based on the
standard, ACI or AACLs access model to allow operations testing.
There was a 'get effective rights' extended operation
defined in the old IETF access control work:
I _think_ that what you are proposing is either similar or identical
to the get effective rights operation.
At least a few LDAP servers implement something like this, e.g. :
-- Howard Chu
Chief Architect, Symas Corp. Director, Highland Sun
Symas: Premier OpenSource Development and Support