shibboleth-dev - RE: OS X info, webDAV use case
Subject: Shibboleth Developers
List archive
- From: "Wilcox, Mark" <>
- To: "Scott Cantor" <>, "Walter Hoehn" <>, "David L. Wasley" <>
- Cc: "Tom Barton" <>, <>
- Subject: RE: OS X info, webDAV use case
- Date: Thu, 25 Sep 2003 15:48:49 -0400
Title: RE: OS X info, webDAV use case
Actually I would argue that comparing Shib to LDAP is that Shib solves a
whole heck of a lot of open LDAP implementation details.
Yes LDAP (and X.500) should have/could have solved lots of similar
issues.
However, nobody has widely deployed them enough to make it workable.
Two major ones come to mind -- referrals and querying an external directory
service.
Referrals -- the notion that a branch in the LDAP server (DIT) returns a
pointer to another LDAP tree, usually on a different server. LDAP servers
generally can return them fine, but all of the popular clients, well, they just
choke on them. Or don't acurately follow them.
Querying an external server -- This should be possible but so few LDAP
servers exist with actual directory information (as opposed to just enough
to perform local authentication) that is publicly accessible -- that
model breaks down. Yes, they do exist in certain locales, but they don't
exist in enough numbers to have any meaning.
Finally Shib does have the capability of doing things that LDAP will not do
-- namely provide a policy service (aka authorization assertions)
and be able to 'possibly' secure each assertion/attribute(s)
seperately via a PKI setup that in the end Shib wins on the
authentication & authorization front.
Ideally LDAP would go back to do what it was supposed to do - provide
a generic white pages protocol and let Kerberos & Shib be the
authentication & authorization services.
Mark
|
- Re: OS X info, webDAV use case, (continued)
- Re: OS X info, webDAV use case, Walter Hoehn, 09/25/2003
- RE: OS X info, webDAV use case, Scott Cantor, 09/25/2003
- Re: OS X info, webDAV use case, Diego R. Lopez, 09/26/2003
- RE: OS X info, webDAV use case, Scott Cantor, 09/24/2003
- RE: OS X info, webDAV use case, Steven_Carmody, 09/24/2003
- Re: OS X info, webDAV use case, Ryan Muldoon, 09/24/2003
- RE: OS X info, webDAV use case, Scott Cantor, 09/24/2003
- Re: webDAV use case, Tom Barton, 09/26/2003
- WAYF redirection vs. sites.xml, c wilper, 09/26/2003
- RE: WAYF redirection vs. sites.xml, Scott Cantor, 09/26/2003
- RE: WAYF redirection vs. sites.xml, c wilper, 09/26/2003
- Re: WAYF redirection vs. sites.xml, Walter Hoehn, 09/29/2003
- RE: WAYF redirection vs. sites.xml, Scott Cantor, 09/26/2003
- WAYF redirection vs. sites.xml, c wilper, 09/26/2003
Archive powered by MHonArc 2.6.16.