Re: Successful LDAP signing test

From: SM <sm_at_resistor.net>
Date: Mon, 22 Feb 2010 01:13:08 -0800

At 00:17 22-02-10, Mike Markley wrote:
>Quick straw poll (which I plan to repeat at the office, where we're
>keenly interested in LDAP-based signing data): does it make more sense
>to have one LDAP attribute for the SigningTable match, or have multiple
>attributes (e.g. opendkimDomain, opendkimMailAddress)? Either is trivial
>to deal with in an LDAP filter, and I suppose specifying both would
>require clear documentation of the precedence. Not sure what's gained by
>having multiple attributes, except maybe looking cleaner.

It's easier to parse the information or extract the list of domains,
for example.

I think that the SigningTable/KeyTable could be
optimized. Currently, we are running two queries. That could have
been done in one query (JOIN) for SQL. That follows the KEY/VALUE
concept discussed on the SigningTable thread.

Regards,
-sm
Received on Mon Feb 22 2010 - 09:13:57 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:32:52 PST