Re: Comments from Christian H. on LDAP

Russ Wright <wright@lbl.gov> Wed, 06 January 1993 00:45 UTC

Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa15356; 5 Jan 93 19:45 EST
Received: from CNRI.RESTON.VA.US by IETF.CNRI.Reston.VA.US id aa15352; 5 Jan 93 19:45 EST
Received: from haig.cs.ucl.ac.uk by CNRI.Reston.VA.US id aa23565; 5 Jan 93 19:46 EST
Received: from bells.cs.ucl.ac.uk by haig.cs.ucl.ac.uk with local SMTP id <g.03550-0@haig.cs.ucl.ac.uk>; Wed, 6 Jan 1993 00:14:55 +0000
Received: from lbl.gov by bells.cs.ucl.ac.uk with Internet SMTP id <g.00510-0@bells.cs.ucl.ac.uk>; Wed, 6 Jan 1993 00:14:49 +0000
Received: from Mac-mailer (macruss.lbl.gov) by lbl.gov (4.1/1.39) id AA20130; Tue, 5 Jan 93 16:15:46 PST
Message-Id: <9301060015.AA20130@lbl.gov>
Date: Tue, 05 Jan 93 16:14:39 -800
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: Russ Wright <wright@lbl.gov>
To: Christian Huitema <Christian.Huitema@sophia.inria.fr>
Subject: Re: Comments from Christian H. on LDAP
Cc: " (Russ Wright)" <wright@lbl.gov>, RARE & IETF OSI-DS wg <osi-ds@cs.ucl.ac.uk>

> Regarding the modify operations: the problem I have is with their
> presence in the DAP in general, not merely in LDAP, for the following
> reasons:
> 
> 1- Allowing real time modification of the data does make the DSA
> software much more complex. You need authentication, but you also need
> journalling of updates, ability to recover, maintenance of index
> files, etc.

I agree.  Some people may not have any use for modifies.  They can buy an 
X.500 product that doesn't support it (and pay less).

> 3- Allowing real time modification *by the end user*, as opposed to
> modification by an administrator, gives the user the impression that
> the X.500 data base contains the "primary" version of the data. What
> happens if user Joe modifies its phone number Thursday but the X.500
> base is restored from an "up to date" version of the payroll data base
> Friday?

If you allow non-authoritative data to be modified in X.500, you must 
provide an automatic way to transfer the information back to the 
authoritative source.  I believe that the University of Michigan is doing 
this.


Russ