Blame | Last modification | View Log | RSS feed
# OpenLDAP X.509 PMI schema# $OpenLDAP$## This work is part of OpenLDAP Software <http://www.openldap.org/>.#### Copyright 1998-2014 The OpenLDAP Foundation.## All rights reserved.#### Redistribution and use in source and binary forms, with or without## modification, are permitted only as authorized by the OpenLDAP## Public License.#### A copy of this license is available in the file LICENSE in the## top-level directory of the distribution or, alternatively, at## <http://www.OpenLDAP.org/license.html>.### Portions Copyright (C) The Internet Society (1997-2006).## All Rights Reserved.## Includes LDAPv3 schema items from:# ITU X.509 (08/2005)## This file was automatically generated from pmi.schema; see that file# for complete references.#dn: cn=pmi,cn=schema,cn=configobjectClass: olcSchemaConfigcn: pmiolcObjectIdentifier: {0}id-oc-pmiUser 2.5.6.24olcObjectIdentifier: {1}id-oc-pmiAA 2.5.6.25olcObjectIdentifier: {2}id-oc-pmiSOA 2.5.6.26olcObjectIdentifier: {3}id-oc-attCertCRLDistributionPts 2.5.6.27olcObjectIdentifier: {4}id-oc-privilegePolicy 2.5.6.32olcObjectIdentifier: {5}id-oc-pmiDelegationPath 2.5.6.33olcObjectIdentifier: {6}id-oc-protectedPrivilegePolicy 2.5.6.34olcObjectIdentifier: {7}id-at-attributeCertificate 2.5.4.58olcObjectIdentifier: {8}id-at-attributeCertificateRevocationList 2.5.4.59olcObjectIdentifier: {9}id-at-aACertificate 2.5.4.61olcObjectIdentifier: {10}id-at-attributeDescriptorCertificate 2.5.4.62olcObjectIdentifier: {11}id-at-attributeAuthorityRevocationList 2.5.4.63olcObjectIdentifier: {12}id-at-privPolicy 2.5.4.71olcObjectIdentifier: {13}id-at-role 2.5.4.72olcObjectIdentifier: {14}id-at-delegationPath 2.5.4.73olcObjectIdentifier: {15}id-at-protPrivPolicy 2.5.4.74olcObjectIdentifier: {16}id-at-xMLPrivilegeInfo 2.5.4.75olcObjectIdentifier: {17}id-at-xMLPprotPrivPolicy 2.5.4.76olcObjectIdentifier: {18}id-mr 2.5.13olcObjectIdentifier: {19}id-mr-attributeCertificateMatch id-mr:42olcObjectIdentifier: {20}id-mr-attributeCertificateExactMatch id-mr:45olcObjectIdentifier: {21}id-mr-holderIssuerMatch id-mr:46olcObjectIdentifier: {22}id-mr-authAttIdMatch id-mr:53olcObjectIdentifier: {23}id-mr-roleSpecCertIdMatch id-mr:54olcObjectIdentifier: {24}id-mr-basicAttConstraintsMatch id-mr:55olcObjectIdentifier: {25}id-mr-delegatedNameConstraintsMatch id-mr:56olcObjectIdentifier: {26}id-mr-timeSpecMatch id-mr:57olcObjectIdentifier: {27}id-mr-attDescriptorMatch id-mr:58olcObjectIdentifier: {28}id-mr-acceptableCertPoliciesMatch id-mr:59olcObjectIdentifier: {29}id-mr-delegationPathMatch id-mr:61olcObjectIdentifier: {30}id-mr-sOAIdentifierMatch id-mr:66olcObjectIdentifier: {31}id-mr-indirectIssuerMatch id-mr:67olcObjectIdentifier: {32}AttributeCertificate 1.3.6.1.4.1.4203.666.11.10.2.1olcObjectIdentifier: {33}CertificateList 1.3.6.1.4.1.1466.115.121.1.9olcObjectIdentifier: {34}AttCertPath 1.3.6.1.4.1.4203.666.11.10.2.4olcObjectIdentifier: {35}PolicySyntax 1.3.6.1.4.1.4203.666.11.10.2.5olcObjectIdentifier: {36}RoleSyntax 1.3.6.1.4.1.4203.666.11.10.2.6olcLdapSyntaxes: {0}( 1.3.6.1.4.1.4203.666.11.10.2.4 DESC 'X.509 PMI attributecartificate path: SEQUENCE OF AttributeCertificate' X-SUBST '1.3.6.1.4.1.1466.115.121.1.15' )olcLdapSyntaxes: {1}( 1.3.6.1.4.1.4203.666.11.10.2.5 DESC 'X.509 PMI policy syntax' X-SUBST '1.3.6.1.4.1.1466.115.121.1.15' )olcLdapSyntaxes: {2}( 1.3.6.1.4.1.4203.666.11.10.2.6 DESC 'X.509 PMI role syntax' X-SUBST '1.3.6.1.4.1.1466.115.121.1.15' )olcAttributeTypes: {0}( id-at-role NAME 'role' DESC 'X.509 Role attribute, use;binary' SYNTAX RoleSyntax )olcAttributeTypes: {1}( id-at-xMLPrivilegeInfo NAME 'xmlPrivilegeInfo' DESC 'X.509 XML privilege information attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )olcAttributeTypes: {2}( id-at-attributeCertificate NAME 'attributeCertificateAttribute' DESC 'X.509 Attribute certificate attribute, use ;binary' EQUALITYattributeCertificateExactMatch SYNTAX AttributeCertificate )olcAttributeTypes: {3}( id-at-aACertificate NAME 'aACertificate' DESC 'X.509 AA certificate attribute, use ;binary' EQUALITY attributeCertificateExactMatchSYNTAX AttributeCertificate )olcAttributeTypes: {4}( id-at-attributeDescriptorCertificate NAME 'attributeDescriptorCertificate' DESC 'X.509 Attribute descriptor certificate attribute,use ;binary' EQUALITY attributeCertificateExactMatch SYNTAX AttributeCertificate )olcAttributeTypes: {5}( id-at-attributeCertificateRevocationList NAME 'attributeCertificateRevocationList' DESC 'X.509 Attribute certificate revocation list attribute, use ;binary' SYNTAX CertificateList X-EQUALITY 'certificateListExactMatch, not implemented yet' )olcAttributeTypes: {6}( id-at-attributeAuthorityRevocationList NAME 'attributeAuthorityRevocationList' DESC 'X.509 AA certificate revocation list attribute, use ;binary' SYNTAX CertificateList X-EQUALITY 'certificateListExactMatch,not implemented yet' )olcAttributeTypes: {7}( id-at-delegationPath NAME 'delegationPath' DESC 'X.509Delegation path attribute, use ;binary' SYNTAX AttCertPath )olcAttributeTypes: {8}( id-at-privPolicy NAME 'privPolicy' DESC 'X.509 Privilege policy attribute, use ;binary' SYNTAX PolicySyntax )olcAttributeTypes: {9}( id-at-protPrivPolicy NAME 'protPrivPolicy' DESC 'X.509Protected privilege policy attribute, use ;binary' EQUALITY attributeCertificateExactMatch SYNTAX AttributeCertificate )olcAttributeTypes: {10}( id-at-xMLPprotPrivPolicy NAME 'xmlPrivPolicy' DESC 'X.509 XML Protected privilege policy attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )olcObjectClasses: {0}( id-oc-pmiUser NAME 'pmiUser' DESC 'X.509 PMI user object class' SUP top AUXILIARY MAY attributeCertificateAttribute )olcObjectClasses: {1}( id-oc-pmiAA NAME 'pmiAA' DESC 'X.509 PMI AA object class' SUP top AUXILIARY MAY ( aACertificate $ attributeCertificateRevocationList$ attributeAuthorityRevocationList ) )olcObjectClasses: {2}( id-oc-pmiSOA NAME 'pmiSOA' DESC 'X.509 PMI SOA object class' SUP top AUXILIARY MAY ( attributeCertificateRevocationList $ attributeAuthorityRevocationList $ attributeDescriptorCertificate ) )olcObjectClasses: {3}( id-oc-attCertCRLDistributionPts NAME 'attCertCRLDistributionPt' DESC 'X.509 Attribute certificate CRL distribution point object class' SUP top AUXILIARY MAY ( attributeCertificateRevocationList $ attributeAuthorityRevocationList ) )olcObjectClasses: {4}( id-oc-pmiDelegationPath NAME 'pmiDelegationPath' DESC 'X.509 PMI delegation path' SUP top AUXILIARY MAY delegationPath )olcObjectClasses: {5}( id-oc-privilegePolicy NAME 'privilegePolicy' DESC 'X.509 Privilege policy object class' SUP top AUXILIARY MAY privPolicy )olcObjectClasses: {6}( id-oc-protectedPrivilegePolicy NAME 'protectedPrivilegePolicy' DESC 'X.509 Protected privilege policy object class' SUP top AUXILIARY MAY protPrivPolicy )