Re: [Ldap-dir] Review Request: The LDAP Binary Option to Proposed Standard

"Kurt D. Zeilenga" <Kurt@OpenLDAP.org> Fri, 24 June 2005 18:19 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1Dlsle-0005Xa-NI; Fri, 24 Jun 2005 14:19:06 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1Dlsld-0005XV-Kh for ldap-dir@megatron.ietf.org; Fri, 24 Jun 2005 14:19:05 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA00556 for <ldap-dir@ietf.org>; Fri, 24 Jun 2005 14:19:04 -0400 (EDT)
Received: from boole.openldap.org ([204.152.186.50] ident=root) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DltAD-0004jo-Nn for ldap-dir@ietf.org; Fri, 24 Jun 2005 14:44:30 -0400
Received: from gyspy.OpenLDAP.org (24-205-218-53.cs-cres.charterpipeline.net [24.205.218.53]) (authenticated bits=0) by boole.openldap.org (8.13.3/8.13.3) with ESMTP id j5OIIW63033697 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 24 Jun 2005 18:18:33 GMT (envelope-from Kurt@OpenLDAP.org)
Message-Id: <6.2.1.2.0.20050624104904.033a8658@mail.openldap.org>
X-Mailer: QUALCOMM Windows Eudora Version 6.2.1.2
Date: Fri, 24 Jun 2005 11:18:06 -0700
To: Ted Hardie <hardie@qualcomm.com>
From: "Kurt D. Zeilenga" <Kurt@OpenLDAP.org>
Subject: Re: [Ldap-dir] Review Request: The LDAP Binary Option to Proposed Standard
In-Reply-To: <p06210201bee1cdde1e14@[192.168.1.4]>
References: <p06210201bee1cdde1e14@[192.168.1.4]>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 386e0819b1192672467565a524848168
Cc: Scott Hollenbeck <sah@428cobrajet.net>, Tim Polk <wpolk@nist.gov>, Stephen Kent <kent@bbn.com>, ldap-dir@ietf.org
X-BeenThere: ldap-dir@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: LDAP Directorate <ldap-dir.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ldap-dir>, <mailto:ldap-dir-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ldap-dir@ietf.org>
List-Help: <mailto:ldap-dir-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ldap-dir>, <mailto:ldap-dir-request@ietf.org?subject=subscribe>
Sender: ldap-dir-bounces@ietf.org
Errors-To: ldap-dir-bounces@ietf.org

As LDAPBIS chair, I note that this I-D has been discussed within
LDAPBIS and PKIX WG circles.  I believe consensus of the LDAPBIS
WG is that this I-D is suitable for publication as a Proposed Standard.
I believe the same holds true for the PKIX WG (the membership
has broad overlap with LDAPBIS).

As an individual contributor to the IETF, I have reviewed this I-D
and find it suitable for publication as a Proposed Standard.  I do
have a couple of minor concerns which likely should be resolved prior
to consideration by the IESG.

The I-D's header contains 'Updates: [SYNTAXES]'
(draft-ietf-ldabis-syntaxes) but the I-D does not actually update
[SYNTAXES].  (If it had, I would have concerns.  But it doesn't,
so...) I suggest this be removed from the I-D header.

Some rewording of the following Introduction passage may be
appropriate.  My main concern here is that the current wording
might lead reviewers and implementors that this is not a sound
solution for the current use of ;binary with certificate
attributes, e.g., userCertificate;binary.  It is a sound solution.

    However the binary option was not included in the newer LDAP
   technical specification due to a lack of consistency in its
   implementation.  This document reintroduces the binary option.
   However, except for the case of certain attribute syntaxes whose
   values are required to BER encoded, no attempt is made here to
   eliminate the known consistency problems.  Rather the focus is on
   capturing current behaviours.  A more thorough solution is
   left for a future specification.

One possible rewording:
  The binary option was not included in the revised
  LDAP technical specification for a variety
  of reasons including implementation inconsistencies.
  This document reintroduces the binary option for
  use with certain attribute syntaxes, such as
  certificate syntax [draft-zeilenga-ldap-x509],
  which specifically require it.   No attempt has
  been made to address use of the ;binary option with
  attribute of syntaxes which do not require its use.
  Unless addressed in a future specification, this
  use is to be avoided.

Regards, Kurt



At 07:51 AM 6/24/2005, Ted Hardie wrote:
>Hi,
>        I've received the following request to shepherd an
>individual submission for proposed standard; I'd appreciate
>review from the directorate.  If folks could review it by
>July 7, I'd appreciate it.  If I get early reviews, I may send
>it out for IETF Last Call concurrent with that period, so
>please feel free to review early.
>                thanks,
>                                Ted Hardie
>
>
>>Date: Fri, 24 Jun 2005 09:48:35 +1000
>>From: Steven Legg <steven.legg@eb2bcom.com>
>>X-Accept-Language: en-us, en
>>To: hardie@qualcomm.com
>>CC: sah@428cobrajet.net
>>Subject: The LDAP Binary Option to Proposed Standard
>>
>>
>>Hi Ted,
>>
>>I wish to submit the individual Internet draft "Lightweight Directory Access
>>Protocol (LDAP): The Binary Encoding Option" (draft-legg-ldap-binary-03.txt)
>>to the IESG for consideration as a Proposed Standard. LDAPbis will be excluding
>>the ";binary" option. This draft reintroduces the ";binary" option for LDAPv3.
>>
>>Note that draft-zeilenga-ldap-x509-01.txt is currently in IESG evaluation and
>>has a normative dependency on this draft.
>>
>>I have indicated in the draft that the specification updates the LDAPbis
>>syntaxes and matching rules specification (draft-ietf-ldapbis-syntaxes-11.txt).
>>Kurt thinks this isn't the case. I will leave the IESG to decide one way or
>>the other.
>>
>>Regards,
>>Steven
>
>
>_______________________________________________
>Ldap-dir mailing list
>Ldap-dir@ietf.org
>https://www1.ietf.org/mailman/listinfo/ldap-dir


_______________________________________________
Ldap-dir mailing list
Ldap-dir@ietf.org
https://www1.ietf.org/mailman/listinfo/ldap-dir