01.12.2014 Views

Entrust Directory Schema Requirements for Entrust 6.0

Entrust Directory Schema Requirements for Entrust 6.0

Entrust Directory Schema Requirements for Entrust 6.0

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Entrust</strong> <strong>Directory</strong> <strong>Schema</strong> <strong>Requirements</strong> <strong>for</strong> <strong>Entrust</strong> <strong>6.0</strong><br />

As of <strong>Entrust</strong> 5.0, policy in<strong>for</strong>mation is published to a new attribute defined as<br />

“entrustPolicyCertificate”. For backwards compatibility with old clients (be<strong>for</strong>e release<br />

5.0) the attributeCertificate is still required; if backwards compatiblity with the old clients<br />

is not required, then the attributeCertificate is not needed.<br />

The X.509 standard defines an attribute called “attributeCertificateAttribute”. This<br />

attribute is used to publish attribute in<strong>for</strong>mation about a user and especially <strong>for</strong> an<br />

Attribute Authority to assign privileges. The auxiliary object class that allows this<br />

attribute to be added to any entry is the pmiUser object class. At the time of publication<br />

of this document, these schema items are defined in X.509 as well as the current working<br />

internet draft:<br />

http://www.ietf.org/internet-drafts/draft-ietf-pkix-ldap-schema-01.txt<br />

<strong>Entrust</strong>/PKI 5.1 has the ability to use issue Attribute Certificates but must be configured<br />

to use the “attributeCertificateAttribute” attribute. <strong>Entrust</strong>/PKI <strong>6.0</strong> will use the<br />

“attributeCertificateAttribute” by default requiring no extra configuration..<br />

24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!