3 == move all mail config into ldap ==
7 * user mail forwards, mail user +extension forwards, mail user +extension pipes, all of it.
8 * service domain aliases files
9 * service domains whitelists/blacklists/neverusers/RBLs
13 * It's all perfect now
17 ** new object classes? Something to differentiate
18 ** Would like to always add NM/DM/etc
19 ** Possibly porter box access for NM/DM ?
22 ** Clean up old expired entries
28 ** LDAP query interface read-only with hidden master
29 ** Privileged modify operations should only be allowed from lo.
32 ** Could we have one, please?
35 * move @d.o to MXes (different source IP to avoid RBL for important mail?)
38 * root everywhere, no authority to speak for team
41 * SSO for web apps (nagios, rt, wiki, etc)
42 * Tied to ud-ldap (but not LDAP password, dammit!)
44 == Munin replacement ==
45 * Something that is scriptable and scales
48 * Way to have per user views. Doable with contacts, just needs to be done
49 * Way to test IPv6, without duplicating all of our config
52 * It'd be nice if service names like db.d.o had sshfp records in DNS. This is tricky because some of the purpose service names are CNAMEs, but not all.