[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-dnsext-apl-rr-01.txt



> For the LDAP folks, take a look at www.ldap.research.netsol.com for
> some ideas on how to get around the 'disconnected islands' aspect of
> LDAP. Its not a true LDAP directory becauses its insanely expensive
> to search the entire tree.

Off-topic observation, their structure is malformed.

For example, I have ntrg.com, ntrg.org and ntrg.net zones. Searching
through their repository returns data that is practically unusable.

You would think ntrg.com would be dc=ntrg,dc=com but instead they use
dc=ntrg,c=us. c=us is an assumption, nor does dc=ntrg,c=us allow for
multiple occurances of dc=ntrg.

ntrg.org and ntrg.net are both stored as dc=ntrg (no secondary qual)
resulting in zone collision in the referral database.

This is a good idea as it provides a psuedo-root for LDAP, whereby any
registered zone in the DNS root zone can have an LDAP link. But the
implementation is really lacking.

-- 
Eric A. Hall                                        http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/


to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.