[389-users] Schema Question

David Partridge dpartridge at tangible.net
Wed Oct 21 15:13:37 UTC 2009


We need to add in the pkiCA, pkiUser, and deltaCRL ObjectClasses to be
in compliance with RFC 4523 to our DS builds.

 

Are these subset of objectClasses from RFC 4523 for Compliance with RFC
4523?  If these are correct I will continue this to make recommended
changes for the Attribute and ObjectClasses defined in RFC 4523 for
00core.ldif in conjunction to my testing to propose to the 389
community.

 

objectClasses: ( 2.5.6.22 NAME 'pkiCA' DESC 'X.509 PKI Certificate
Authority' SUP top AUXILIARY MAY ( cACertificate $
certificateRevocationList $ authorityRevocationList $
crossCertificatePair ) X-ORIGIN 'RFC 4523' )

 

objectClasses: ( 2.5.6.23 NAME 'deltaCRL' DESC 'X.509 delta CRL' SUP top
AUXILIARY MAY deltaRevocationList X-ORIGIN 'RFC 4523') 

 

objectClasses: ( 2.5.6.21 NAME 'pkiUser'  DESC 'X.509 PKI User' SUP top
AUXILIARY MAY userCertificate X-ORIGIN 'RFC 4523')

 

Thanks

 

David M. Partridge

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-directory-users/attachments/20091021/6e1623e3/attachment.htm>


More information about the Fedora-directory-users mailing list