[Ietf-not43] First draft on Relay bags in FIRS

Steven Legg steven.legg at adacel.com.au
Fri Aug 15 13:05:18 EDT 2003


Eric & Peter,

Eric A. Hall wrote:
> on 8/13/2003 8:37 AM Peter Gietz wrote:
> 
> > please find attached a first version of the promissed Draft on FIRS 
> > Relay Bag.
> 
> >    A FIRS client SHOULD evaluate if the server it initially 
> connects to
> >    supports this feature, by checking if the controlType Object
> >    Identifier of the control specified in this document
> >    (relayBagSearchOID) is stored in the attribute 
> supportedControl of
> >    the root DSE entry, which is specified in [RFC2251], section 3.4.
> 
> I'll put some more time into this in a couple of days but the 
> first thing
> that jumps out at me is that this should be a MAY instead of 
> a SHOULD. Too
> many round-trips spent on query setup will make this service 
> unusable for
> fast lookups. There might be some other options for dealing 
> with the need
> for this, such as having the control returned as a bind 
> response similar
> to firsVersion.

I don't see a need for any sort of check. The control in the request
is required to be marked critical. The client should just send in its
query with the control attached. FIRS-aware LDAP servers will do their
job. Conformant LDAP servers that are not FIRS-aware will respond with
the error unsupportedCriticalExtension.

Regards,
Steven

> 
> Also, does there need to be any wording on how the data should be
> encapsulated within an LDAP URL?
> 
> -- 
> Eric A. Hall                                        
http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/

_______________________________________________
Ietf-not43 mailing list
Ietf-not43 at lists.verisignlabs.com
https://lists.verisignlabs.com/mailman/listinfo/ietf-not43



More information about the Ietf-not43 mailing list