亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? draft-ietf-pkix-ldap-pmi-schema-00.txt

?? PKIX的RFC英文文檔
?? TXT
?? 第 1 頁 / 共 4 頁
字號:
INTERNET-DRAFT                                            D. W. ChadwickPKIX WG                       		         University of Salford      Intended Category: Standards Track                               S. Legg                                                              Adacel TechnologiesExpires on 27 December 2002                                 27 June 2002                 Internet X.509 Public Key Infrastructure                    LDAP Schema and Syntaxes for PMIs                 <draft-ietf-pkix-ldap-pmi-schema-00.txt>Copyright (C) The Internet Society (2002). All Rights Reserved.STATUS OF THIS MEMOThis document is an Internet-Draft and is in full conformance withall the provisions of Section 10 of RFC2026 [1].Internet-Drafts are working documents of the Internet EngineeringTask Force (IETF), its areas, and its working groups. Note that othergroups may also distribute working documents as Internet-Drafts.Internet-Drafts are draft documents valid for a maximum of six monthsand may be updated, replaced, or obsoleted by other documents at anytime. It is inappropriate to use Internet-Drafts as referencematerial or to cite them other than as "work in progress."The list of current Internet-Drafts can be accessed athttp://www.ietf.org/ietf/1id-abstracts.txt.The list of Internet-Draft Shadow Directories can be accessed athttp://www.ietf.org/shadow.html.Comments and suggestions on this document are encouraged. Comments on this document should be sent to the PKIX working group discussion list<ietf-pkix@imc.org> or directly to the authors.ABSTRACTThis document describes LDAP schema features that are needed to support X.509 Privilege Management Infrastructures. Specifically, X.509 attribute types, object classes, matching rules, attribute value syntaxes and attribute value assertion syntaxes needed for PMIs are defined.The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT","SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and  "OPTIONAL" in thisdocument are to be interpreted as described in RFC 2119 [5].1. IntroductionLDAPv3 [4] servers are a natural repository for X.509 PMI components e.g. attribute certificate attributes, attribute certificate revocation lists and attribute authority entries. This [document/ID/standard] defines the LDAP subschema needed for storing X.509 PMI information in LDAPv3 servers and for accessing this information e.g. searching for it, updating it, and perform comparisons on it.2. Subschema PublishingLDAPv3 allows the subschema supported by a server to be published in a subschema subentry. Clients following this profile which support the Search operation containing an extensible matching rule SHOULD use the subschemaSubentry attribute in the root DSE to find the subschemaSubentry, and SHOULD use the matchingRule and matchingRuleUse operational attributes in the subschema subentry in order to determine whether the server supports the various matching rules described below. Servers that support extensible matching SHOULD publish the matching rules they support in the matchingRule and matchingRuleUse operational attributes.3. PMI Attributes and SyntaxesLDAP servers MAY store any type of PMI attribute, and LDAP clients MAY request them to be returned by adding them to the Search Request AttributeDescriptionList (either explicitly or implicity via requesting all user attributes). 3.1 Attribute Certificate AttributeThe attributeCertificateAttribute is defined in 17.2.1 of [9]. It is used to hold the attribute certificates of a user. The LDAPspecific encoding for values of this attribute is described in section 3.4.      attributeCertificateAttribute  ATTRIBUTE ::= {	WITH SYNTAX		AttributeCertificate	EQUALITY MATCHING RULE	attributeCertificateExactMatch	ID { joint-iso-ccitt(2) ds(5) attributeType(4)		attributeCertificate(58) } }The corresponding LDAP description is      ( 2.5.4.58 NAME 'attributeCertificateAttribute'      EQUALITY attributeCertificateExactMatch      SYNTAX 1.2.826.0.1.3344810.7.5 )3.2 Attribute Authority Certificate AttributeThe attribute authority attribute certificate is defined in 17.2.2 of [9]. The aAcertificate attribute holds the privileges of an attribute authority. The LDAPspecific encoding for values of this attribute is described in section 3.4.      aACertificate  ATTRIBUTE ::= {	WITH SYNTAX		AttributeCertificate	EQUALITY MATCHING RULE	attributeCertificateExactMatch	ID { joint-iso-ccitt(2) ds(5) attributeType(4)		aACertificate(61) } }The corresponding LDAP description is      ( 2.5.4.61 NAME 'aACertificate'      EQUALITY attributeCertificateExactMatch      SYNTAX 1.2.826.0.1.3344810.7.5 )3.3 Attribute Descriptor Certificate AttributeThe attributeDescriptorCertificate attribute is defined in 17.2.3 of [9]. The certificate is self signed by a source of authority and holds a description of the privilege and its delegation rules. The LDAPspecific encoding for values of this attribute is described in section 3.4.      attributeDescriptorCertificate  ATTRIBUTE ::= {	WITH SYNTAX		AttributeCertificate 	EQUALITY MATCHING RULE	attributeCertificateExactMatch 	ID { joint-iso-ccitt(2) ds(5) attributeType(4)		attributeDescriptorCertificate (62) } }The corresponding LDAP description is      ( 2.5.4.62 NAME 'attributeDescriptorCertificate'      EQUALITY attributeCertificateExactMatch      SYNTAX 1.2.826.0.1.3344810.7.5 )3.4 Attribute  Certificate SyntaxThe LDAP-specific encoding for a certificate value is the octet string that results from BER/DER-encoding an X.509 attribute certificate.  The following string states the OID assigned to this syntax:      (1.2.826.0.1.3344810.7.5 DESC 'Attribute Certificate' )Servers MUST preserve values in this syntax exactly as given when storing and retrieving them. Transformation of these values between storage and retrieval MUST NOT take place.3.5 Attribute Certificate Revocation List AttributeThe attributeCertificateRevocationList attribute is defined in section 17.2.4 of [9]. It holds a list of attribute certificates that have been revoked. The LDAP-specific encoding for values of this attribute is described in [2].      attributeCertificateRevocationList  ATTRIBUTE ::= {	WITH SYNTAX		CertificateList	EQUALITY MATCHING RULE	certificateListExactMatch	ID { joint-iso-ccitt(2) ds(5) attributeType(4) aCRL(59) } }The corresponding LDAP description is      ( 2.5.4.59 NAME 'attributeCertificateRevocationList'      EQUALITY certificateListExactMatch      SYNTAX 1.3.6.1.4.1.1466.115.121.1.9 )3.6 Attribute Authority Certificate Revocation List AttributeThe attribute authority certificate revocation list attribute is defined in section 17.2.5 of [9]. It holds a list of AA certificates that have been revoked. The LDAP-specific encoding for values of this attribute is described in [2].      attributeAuthorityRevocationList  ATTRIBUTE ::= {	WITH SYNTAX		CertificateList	EQUALITY MATCHING RULE 	certificateListExactMatch	ID { joint-iso-ccitt(2) ds(5) attributeType(4) aARL(63) } }The corresponding LDAP description is      ( 2.5.4.63 NAME 'attributeAuthorityRevocationList'      EQUALITY certificateListExactMatch      SYNTAX 1.3.6.1.4.1.1466.115.121.1.9 )3.7 Delegation Path AttributeThe delegation path attribute contains delegation paths, each consisting of a sequence of attribute certificates      delegationPath	ATTRIBUTE	::= {	WITH SYNTAX	AttCertPath	ID ( joint-iso-ccitt(2) ds(5) attributeType(4) delPath (73) } )      AttCertPath	::=	SEQUENCE OF AttributeCertificateThe corresponding LDAP description is      ( 2.5.4.73 NAME 'delegationPath'      SYNTAX 1.2.826.0.1.3344810.7.21 )The following description is copied from X.509 (2000) [9]. "This attribute can be stored in the AA directory entry and would contain some delegation paths from that AA to other AAs. This attribute, if used, enables more efficient retrieval of delegated attribute certificates that form frequently used delegation paths. As such, there are no specific requirements for this attribute to be used and the set of values that are stored in the attribute is unlikely to represent the complete set of delegation paths for any given AA."3.8 Delegation Path SyntaxThe LDAP-specific encoding for a delegation path value is the octet string that results from the BER/DER-encoding of a sequence of attribute certificates.  The following string states the OID assigned to this syntax:      ( 1.2.826.0.1.3344810.7.21 DESC 'Attribute certificate delegation        path' )Servers MUST preserve values in this syntax exactly as given when storing and retrieving them.4 PMI Matching RulesLDAP servers that support the storage of attributes with the AttributeCertificate syntax MUST support searching for entries containing specific attribute certificates, via the attributeCertificateExactMatch matching rule. LDAPv3Servers MAY support flexible matching for any attributes with the AttributeCertificate syntax via the attributeCertificateMatch matching rule or any of the matching rules defined for the certificate extensions. LDAPv3 servers SHOULD publish the matching rules that they do support in the matchingRule and matchingRuleUse operational attributes of the subschema subentry. If the server does support flexible matching (either via attributeCertificateMatch or some other matching rule), then the extensibleMatch filter of the Search request MUST be supported.  LDAPv3 clients MAY support the extensibleMatch filter of the Search operation, along one or more of the optional elements of attributeCertificateMatch or any of the certificate extension matching rules.The LDAP-specific (i.e. string) encodings for the assertion syntaxes defined in this document are specified by the Generic String Encoding Rules (GSER) [3]. The ABNF in this document for these assertion syntaxes is provided only as a convenience and is equivalent to the encoding specified by the application of [3]. (The only exception to this is the alternative simple endoding for attributeCertificatExactMatch.) Since the associated ASN.1 types for the assertion syntaxes described here may be extended in future editions of X.509 [9], the provided ABNF should be regarded as a snapshot in time. The LDAP-specific encoding for any extension to a syntax's underlying ASN.1 type can be determined from [3]. In the event that there is a discrepancy between the ABNF in this document and the encoding determined by [3], [3] is to be taken as definitive. 4.1 Attribute Certificate Exact MatchThe equality matching rule for all types of attribute withAttributeCertificate syntax is the attributeCertificateExactMatch,This is defined in 17.3.1 of [9]. It is reproduced below for theconvenience of the reader (but see Outstanding Issues).      attributeCertificateExactMatch  MATCHING-RULE ::= {	SYNTAX	AttributeCertificateExactAssertion	ID	{ joint-iso-ccitt(2) ds(5) mr (13)		    attributeCertificateExactMatch (45) } }      AttributeCertificateExactAssertion ::= SEQUENCE {	serialNumber	CertificateSerialNumber,	issuer		AttCertIssuer }      CertificateSerialNumber	::= INTEGER      AttCertIssuer ::= 	[0]	SEQUENCE {       issuerName			GeneralNames  OPTIONAL,      baseCertificateID	[0]	IssuerSerial  OPTIONAL,      objectDigestInfo	[1]	ObjectDigestInfo  OPTIONAL }  -- At least one component shall be present      IssuerSerial  ::=  SEQUENCE {	issuer		GeneralNames,	serial		CertificateSerialNumber,	issuerUID		UniqueIdentifier OPTIONAL }      UniqueIdentifier ::= BIT STRING      ObjectDigestInfo    ::= SEQUENCE {	digestedObjectType  ENUMERATED {		publicKey       		(0),		publicKeyCert        	(1),		otherObjectTypes     	(2) },	otherObjectTypeID   	OBJECT IDENTIFIER  OPTIONAL,	digestAlgorithm     	AlgorithmIdentifier,	objectDigest        	BIT STRING }The LDAP definition for the above matching rule is:        ( 2.5.13.45 NAME 'attributeCertificateExactMatch'         SYNTAX 1.2.826.0.1.3344810.7.6)The syntax definition is:         (1.2.826.0.1.3344810.7.6 DESC 'Attribute certificate exact          assertion (serial number and issuer details)' )The LDAP-specific encoding of an assertion value of this syntax is a choice between - the GSER encoding <GSERAttributeCertificateExactAssertion> defined by [3] and - the simple encoding <SimpleCertificateExactAssertion> defined in [2]. The full syntax is described by the following Augmented BNF [10]:AttributeCertificateExactAssertion =                             GSERAttributeCertificateExactAssertion /                            SimpleCertificateExactAssertion GSERAttributeCertificateExactAssertion = "{" sp acea-serialNumber ","                                         sp acea-issuer                                         sp "}"acea-serialNumber  = id-serialNumber msp CertificateSerialNumberacea-issuer        = id-issuer       msp AttCertIssuer

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
九九热在线视频观看这里只有精品| 中文字幕av一区 二区| 欧美va在线播放| 国产视频在线观看一区二区三区| 国产精品国产三级国产aⅴ入口| 国产精品嫩草99a| 亚洲一区二区精品久久av| 美女视频黄 久久| 国产不卡视频在线播放| 91国偷自产一区二区三区成为亚洲经典 | 裸体健美xxxx欧美裸体表演| 国产一区 二区 三区一级| 91在线观看一区二区| 欧美日韩在线精品一区二区三区激情 | 欧美日韩一区国产| 制服丝袜激情欧洲亚洲| 久久久精品黄色| 一卡二卡欧美日韩| 国内精品自线一区二区三区视频| av在线不卡免费看| 欧美一区二区福利视频| 中文字幕av资源一区| 三级在线观看一区二区 | 国产精品丝袜久久久久久app| 亚洲激情自拍偷拍| 麻豆精品新av中文字幕| 97久久人人超碰| 欧美刺激午夜性久久久久久久 | 国产河南妇女毛片精品久久久 | 一区二区久久久| 国产综合久久久久影院| 日本精品一级二级| 久久老女人爱爱| 亚洲电影你懂得| 成人在线视频一区二区| 日韩一级精品视频在线观看| 一区二区三区中文字幕| 国产乱码字幕精品高清av| 欧美日韩欧美一区二区| 国产精品久久久久久久久免费桃花 | 亚洲成人黄色影院| 国产91精品欧美| 日韩精品一区二| 亚洲一区中文日韩| 波多野结衣91| 欧美成人a视频| 日日摸夜夜添夜夜添亚洲女人| 波多野结衣在线一区| 精品1区2区在线观看| 热久久国产精品| 在线观看一区不卡| 日韩一区有码在线| 国产a级毛片一区| 欧美岛国在线观看| 日韩中文字幕区一区有砖一区 | 欧美国产1区2区| 激情都市一区二区| 日韩欧美一级精品久久| 天堂蜜桃91精品| 日本电影欧美片| 最新国产精品久久精品| 丰满亚洲少妇av| 久久精品在这里| 国产精品自拍三区| 精品日韩一区二区| 麻豆国产欧美一区二区三区| 欧美日韩国产精选| 亚洲二区视频在线| 欧美日韩精品欧美日韩精品一| 一二三区精品视频| 色欧美日韩亚洲| 亚洲精品久久7777| 一本久久精品一区二区| 亚洲另类春色校园小说| 色综合天天狠狠| 亚洲婷婷综合久久一本伊一区| av福利精品导航| 成人欧美一区二区三区在线播放| 成人涩涩免费视频| 国产精品免费视频观看| 白白色 亚洲乱淫| 亚洲三级电影网站| 色菇凉天天综合网| 洋洋成人永久网站入口| 欧美性大战久久久久久久| 亚洲五码中文字幕| 欧美群妇大交群中文字幕| 日韩黄色免费电影| 日韩精品一区国产麻豆| 国产一区二区三区av电影| 国产日韩精品一区二区三区| 丁香一区二区三区| 自拍偷在线精品自拍偷无码专区 | 亚洲精品视频在线观看免费| 99re成人精品视频| 亚洲午夜精品久久久久久久久| 在线播放视频一区| 久久精品国产亚洲aⅴ| 久久久美女毛片| 成人精品gif动图一区| 亚洲欧洲综合另类在线| 精品视频在线免费看| 麻豆极品一区二区三区| 国产欧美日韩三区| 色综合激情五月| 日本怡春院一区二区| 久久久不卡影院| 99久久婷婷国产| 图片区小说区区亚洲影院| 日韩久久免费av| 成人性生交大片免费看中文| 一区二区免费在线| 日韩欧美在线综合网| 高清shemale亚洲人妖| 一区二区三区不卡视频| 日韩精品一区二区三区三区免费| 成人免费看视频| 亚洲成av人综合在线观看| www日韩大片| 91免费在线视频观看| 日韩av不卡一区二区| 亚洲国产精品成人久久综合一区| 欧美影院精品一区| 狠狠狠色丁香婷婷综合激情| 亚洲男同1069视频| 欧美一区二区美女| av电影在线观看一区| 免费看黄色91| 国产精品国模大尺度视频| 欧美精品亚洲二区| 成人av网在线| 日本在线不卡视频| 亚洲欧美乱综合| 精品国产伦一区二区三区免费| 99久久久精品免费观看国产蜜| 强制捆绑调教一区二区| 中文字幕在线不卡一区二区三区| 制服.丝袜.亚洲.中文.综合| 成人黄动漫网站免费app| 日韩国产在线观看一区| 国产精品久久久久一区二区三区共| 欧美视频日韩视频| 99精品在线观看视频| 另类人妖一区二区av| 一区二区三国产精华液| 亚洲国产成人午夜在线一区| 777亚洲妇女| 99久久婷婷国产综合精品| 黑人精品欧美一区二区蜜桃 | 欧美日韩成人一区| 不卡的电影网站| 国产一区二区三区黄视频 | 捆绑调教美女网站视频一区| 一区二区三区精品在线观看| 久久九九国产精品| 在线成人av影院| 91视视频在线直接观看在线看网页在线看| 免费人成网站在线观看欧美高清| 亚洲精品少妇30p| 亚洲国产精品av| 26uuu久久天堂性欧美| 欧美日韩一区成人| 91啪在线观看| 成人动漫一区二区三区| 国产一区二区影院| 蜜臀91精品一区二区三区 | 日韩一区二区在线播放| 欧美日韩一区二区在线观看| 91色在线porny| 高清shemale亚洲人妖| 国产精品亚洲一区二区三区在线| 蜜臀av性久久久久蜜臀av麻豆| 午夜影视日本亚洲欧洲精品| 亚洲另类在线制服丝袜| 亚洲人亚洲人成电影网站色| 国产精品天干天干在线综合| 久久久国产一区二区三区四区小说| 欧美成人午夜电影| 日韩精品一区二区三区四区视频| 91精品久久久久久久99蜜桃| 欧美理论电影在线| 欧美欧美欧美欧美| 欧美挠脚心视频网站| 欧美群妇大交群的观看方式| 欧美精品一卡二卡| 欧美一区二区在线看| 日韩一区二区三区四区| 日韩一级片在线观看| 精品嫩草影院久久| 精品福利一区二区三区免费视频| 欧美一区二区免费| 26uuu国产电影一区二区| 久久先锋影音av| 欧美国产成人精品| 亚洲品质自拍视频| 亚洲已满18点击进入久久| 午夜精品福利一区二区蜜股av| 亚洲午夜电影网| 日韩高清不卡一区二区| 久久精品国产亚洲a|