1 1.1 lukem 2 1.1 lukem 3 1.1 lukem 4 1.1 lukem 5 1.1 lukem 6 1.1 lukem 7 1.1 lukem Network Working Group K. Zeilenga, Ed. 8 1.1 lukem Request for Comments: 4524 OpenLDAP Foundation 9 1.1 lukem Obsoletes: 1274 June 2006 10 1.1 lukem Updates: 2247, 2798 11 1.1 lukem Category: Standards Track 12 1.1 lukem 13 1.1 lukem 14 1.1 lukem COSINE LDAP/X.500 Schema 15 1.1 lukem 16 1.1 lukem Status of This Memo 17 1.1 lukem 18 1.1 lukem This document specifies an Internet standards track protocol for the 19 1.1 lukem Internet community, and requests discussion and suggestions for 20 1.1 lukem improvements. Please refer to the current edition of the "Internet 21 1.1 lukem Official Protocol Standards" (STD 1) for the standardization state 22 1.1 lukem and status of this protocol. Distribution of this memo is unlimited. 23 1.1 lukem 24 1.1 lukem Copyright Notice 25 1.1 lukem 26 1.1 lukem Copyright (C) The Internet Society (2006). 27 1.1 lukem 28 1.1 lukem Abstract 29 1.1 lukem 30 1.1 lukem This document provides a collection of schema elements for use with 31 1.1 lukem the Lightweight Directory Access Protocol (LDAP) from the COSINE and 32 1.1 lukem Internet X.500 pilot projects. 33 1.1 lukem 34 1.1 lukem This document obsoletes RFC 1274 and updates RFCs 2247 and 2798. 35 1.1 lukem 36 1.1 lukem Table of Contents 37 1.1 lukem 38 1.1 lukem 1. Introduction ....................................................3 39 1.1 lukem 1.1. Relationship to Other Documents ............................3 40 1.1 lukem 1.2. Terminology and Conventions ................................4 41 1.1 lukem 2. COSINE Attribute Types ..........................................4 42 1.1 lukem 2.1. associatedDomain ...........................................4 43 1.1 lukem 2.2. associatedName .............................................5 44 1.1 lukem 2.3. buildingName ...............................................5 45 1.1 lukem 2.4. co .........................................................5 46 1.1 lukem 2.5. documentAuthor .............................................6 47 1.1 lukem 2.6. documentIdentifier .........................................6 48 1.1 lukem 2.7. documentLocation ...........................................6 49 1.1 lukem 2.8. documentPublisher ..........................................7 50 1.1 lukem 2.9. documentTitle ..............................................7 51 1.1 lukem 2.10. documentVersion ...........................................7 52 1.1 lukem 2.11. drink .....................................................8 53 1.1 lukem 2.12. homePhone .................................................8 54 1.1 lukem 2.13. homePostalAddress .........................................8 55 1.1 lukem 56 1.1 lukem 57 1.1 lukem 58 1.1 lukem Zeilenga Standards Track [Page 1] 59 1.1 lukem 61 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 62 1.1 lukem 63 1.1 lukem 64 1.1 lukem 2.14. host ......................................................9 65 1.1 lukem 2.15. info ......................................................9 66 1.1 lukem 2.16. mail ......................................................9 67 1.1 lukem 2.17. manager ..................................................10 68 1.1 lukem 2.18. mobile ...................................................10 69 1.1 lukem 2.19. organizationalStatus .....................................11 70 1.1 lukem 2.20. pager ....................................................11 71 1.1 lukem 2.21. personalTitle ............................................11 72 1.1 lukem 2.22. roomNumber ...............................................12 73 1.1 lukem 2.23. secretary ................................................12 74 1.1 lukem 2.24. uniqueIdentifier .........................................12 75 1.1 lukem 2.25. userClass ................................................13 76 1.1 lukem 3. COSINE Object Classes ..........................................13 77 1.1 lukem 3.1. account ...................................................13 78 1.1 lukem 3.2. document ..................................................14 79 1.1 lukem 3.3. documentSeries ............................................14 80 1.1 lukem 3.4. domain ....................................................15 81 1.1 lukem 3.5. domainRelatedObject .......................................16 82 1.1 lukem 3.6. friendlyCountry ...........................................16 83 1.1 lukem 3.7. rFC822LocalPart ...........................................17 84 1.1 lukem 3.8. room ......................................................18 85 1.1 lukem 3.9. simpleSecurityObject ......................................18 86 1.1 lukem 4. Security Considerations ........................................18 87 1.1 lukem 5. IANA Considerations ............................................19 88 1.1 lukem 6. Acknowledgements ...............................................20 89 1.1 lukem 7. References .....................................................20 90 1.1 lukem 7.1. Normative References ......................................20 91 1.1 lukem 7.2. Informative References ....................................21 92 1.1 lukem Appendix A. Changes since RFC 1274 ...............................23 93 1.1 lukem A.1. LDAP Short Names .........................................23 94 1.1 lukem A.2. pilotObject ..............................................23 95 1.1 lukem A.3. pilotPerson ..............................................23 96 1.1 lukem A.4. dNSDomain ................................................24 97 1.1 lukem A.5. pilotDSA and qualityLabelledData .........................24 98 1.1 lukem A.6. Attribute Syntaxes .......................................24 99 1.1 lukem Appendix B. Changes since RFC 2247 ...............................24 100 1.1 lukem 101 1.1 lukem 102 1.1 lukem 103 1.1 lukem 104 1.1 lukem 105 1.1 lukem 106 1.1 lukem 107 1.1 lukem 108 1.1 lukem 109 1.1 lukem 110 1.1 lukem 111 1.1 lukem 112 1.1 lukem 113 1.1 lukem 114 1.1 lukem 115 1.1 lukem Zeilenga Standards Track [Page 2] 116 1.1 lukem 118 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 119 1.1 lukem 120 1.1 lukem 121 1.1 lukem 1. Introduction 122 1.1 lukem 123 1.1 lukem In the late 1980s, X.500 Directory Services were standardized by the 124 1.1 lukem CCITT (Commite' Consultatif International de Telegraphique et 125 1.1 lukem Telephonique), now a part of the ITU (International Telephone Union). 126 1.1 lukem This lead to Directory Service piloting activities in the early 127 1.1 lukem 1990s, including the COSINE (Co-operation and Open Systems 128 1.1 lukem Interconnection in Europe) PARADISE Project pilot [COSINEpilot] in 129 1.1 lukem Europe. Motivated by needs for large-scale directory pilots, RFC 130 1.1 lukem 1274 was published to standardize the directory schema and naming 131 1.1 lukem architecture for use in the COSINE and other Internet X.500 pilots 132 1.1 lukem [RFC1274]. 133 1.1 lukem 134 1.1 lukem In the years that followed, X.500 Directory Services have evolved to 135 1.1 lukem incorporate new capabilities and even new protocols. In particular, 136 1.1 lukem the Lightweight Directory Access Protocol (LDAP) [RFC4510] was 137 1.1 lukem introduced in the early 1990s [RFC1487], with Version 3 of LDAP 138 1.1 lukem introduced in the late 1990s [RFC2251] and subsequently revised in 139 1.1 lukem 2005 [RFC4510]. 140 1.1 lukem 141 1.1 lukem While much of the material in RFC 1274 has been superceded by 142 1.1 lukem subsequently published ITU-T Recommendations and IETF RFCs, many of 143 1.1 lukem the schema elements lack standardized schema descriptions for use in 144 1.1 lukem modern X.500 and LDAP directory services despite the fact that these 145 1.1 lukem schema elements are in wide use today. As the old schema 146 1.1 lukem descriptions cannot be used without adaptation, interoperability 147 1.1 lukem issues may arise due to lack of standardized modern schema 148 1.1 lukem descriptions. 149 1.1 lukem 150 1.1 lukem This document addresses these issues by offering standardized schema 151 1.1 lukem descriptions, where needed, for widely used COSINE schema elements. 152 1.1 lukem 153 1.1 lukem 1.1. Relationship to Other Documents 154 1.1 lukem 155 1.1 lukem This document, together with [RFC4519] and [RFC4517], obsoletes RFC 156 1.1 lukem 1274 in its entirety. [RFC4519] replaces Sections 9.3.1 (Userid) and 157 1.1 lukem 9.3.21 (Domain Component) of RFC 1274. [RFC4517] replaces Section 158 1.1 lukem 9.4 (Generally useful syntaxes) of RFC 1274. 159 1.1 lukem 160 1.1 lukem This document replaces the remainder of RFC 1274. Appendix A 161 1.1 lukem discusses changes since RFC 1274, as well as why certain schema 162 1.1 lukem elements were not brought forward in this revision of the COSINE 163 1.1 lukem schema. All elements not brought are to be regarded as Historic. 164 1.1 lukem 165 1.1 lukem The description of the 'domain' object class provided in this 166 1.1 lukem document supercedes that found in RFC 2247. That is, Section 3.4 of 167 1.1 lukem this document replaces Section 5.2 of [RFC2247]. 168 1.1 lukem 169 1.1 lukem 170 1.1 lukem 171 1.1 lukem 172 1.1 lukem Zeilenga Standards Track [Page 3] 173 1.1 lukem 175 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 176 1.1 lukem 177 1.1 lukem 178 1.1 lukem Some of the schema elements specified here were described in RFC 2798 179 1.1 lukem (inetOrgPerson schema). This document supersedes these descriptions. 180 1.1 lukem This document, together with [RFC4519], replaces Section 9.1.3 of RFC 181 1.1 lukem 2798. 182 1.1 lukem 183 1.1 lukem 1.2. Terminology and Conventions 184 1.1 lukem 185 1.1 lukem The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", 186 1.1 lukem "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this 187 1.1 lukem document are to be interpreted as described in BCP 14 [RFC2119]. 188 1.1 lukem 189 1.1 lukem DIT stands for Directory Information Tree. 190 1.1 lukem DN stands for Distinguished Name. 191 1.1 lukem DSA stands for Directory System Agent, a server. 192 1.1 lukem DSE stands for DSA-Specific Entry. 193 1.1 lukem DUA stands for Directory User Agent, a client. 194 1.1 lukem 195 1.1 lukem These terms are discussed in [RFC4512]. 196 1.1 lukem 197 1.1 lukem Schema definitions are provided using LDAP description formats 198 1.1 lukem [RFC4512]. Definitions provided here are formatted (line wrapped) 199 1.1 lukem for readability. 200 1.1 lukem 201 1.1 lukem 2. COSINE Attribute Types 202 1.1 lukem 203 1.1 lukem This section details COSINE attribute types for use in LDAP. 204 1.1 lukem 205 1.1 lukem 2.1. associatedDomain 206 1.1 lukem 207 1.1 lukem The 'associatedDomain' attribute specifies DNS [RFC1034][RFC2181] 208 1.1 lukem host names [RFC1123] that are associated with an object. That is, 209 1.1 lukem values of this attribute should conform to the following ABNF: 210 1.1 lukem 211 1.1 lukem domain = root / label *( DOT label ) 212 1.1 lukem root = SPACE 213 1.1 lukem label = LETDIG [ *61( LETDIG / HYPHEN ) LETDIG ] 214 1.1 lukem LETDIG = %x30-39 / %x41-5A / %x61-7A ; "0" - "9" / "A"-"Z" / "a"-"z" 215 1.1 lukem SPACE = %x20 ; space (" ") 216 1.1 lukem HYPHEN = %x2D ; hyphen ("-") 217 1.1 lukem DOT = %x2E ; period (".") 218 1.1 lukem 219 1.1 lukem For example, the entry in the DIT with a DN <DC=example,DC=com> might 220 1.1 lukem have an associated domain of "example.com". 221 1.1 lukem 222 1.1 lukem ( 0.9.2342.19200300.100.1.37 NAME 'associatedDomain' 223 1.1 lukem EQUALITY caseIgnoreIA5Match 224 1.1 lukem SUBSTR caseIgnoreIA5SubstringsMatch 225 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) 226 1.1 lukem 227 1.1 lukem 228 1.1 lukem 229 1.1 lukem Zeilenga Standards Track [Page 4] 230 1.1 lukem 232 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 233 1.1 lukem 234 1.1 lukem 235 1.1 lukem The IA5String (1.3.6.1.4.1.1466.115.121.1.26) syntax and the 236 1.1 lukem 'caseIgnoreIA5Match' and 'caseIgnoreIA5SubstringsMatch' rules are 237 1.1 lukem described in [RFC4517]. 238 1.1 lukem 239 1.1 lukem Note that the directory will not ensure that values of this attribute 240 1.1 lukem conform to the <domain> production provided above. It is the 241 1.1 lukem application's responsibility to ensure that domains it stores in this 242 1.1 lukem attribute are appropriately represented. 243 1.1 lukem 244 1.1 lukem Also note that applications supporting Internationalized Domain Names 245 1.1 lukem SHALL use the ToASCII method [RFC3490] to produce <label> components 246 1.1 lukem of the <domain> production. 247 1.1 lukem 248 1.1 lukem 2.2. associatedName 249 1.1 lukem 250 1.1 lukem The 'associatedName' attribute specifies names of entries in the 251 1.1 lukem organizational DIT associated with a DNS domain [RFC1034][RFC2181]. 252 1.1 lukem 253 1.1 lukem ( 0.9.2342.19200300.100.1.38 NAME 'associatedName' 254 1.1 lukem EQUALITY distinguishedNameMatch 255 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 ) 256 1.1 lukem 257 1.1 lukem The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the 258 1.1 lukem 'distinguishedNameMatch' rule are described in [RFC4517]. 259 1.1 lukem 260 1.1 lukem 2.3. buildingName 261 1.1 lukem 262 1.1 lukem The 'buildingName' attribute specifies names of the buildings where 263 1.1 lukem an organization or organizational unit is based, for example, "The 264 1.1 lukem White House". 265 1.1 lukem 266 1.1 lukem ( 0.9.2342.19200300.100.1.48 NAME 'buildingName' 267 1.1 lukem EQUALITY caseIgnoreMatch 268 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 269 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 270 1.1 lukem 271 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 272 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 273 1.1 lukem in [RFC4517]. 274 1.1 lukem 275 1.1 lukem 2.4. co 276 1.1 lukem 277 1.1 lukem The 'co' (Friendly Country Name) attribute specifies names of 278 1.1 lukem countries in human-readable format, for example, "Germany" and 279 1.1 lukem "Federal Republic of Germany". It is commonly used in conjunction 280 1.1 lukem with the 'c' (Country Name) [RFC4519] attribute (whose values are 281 1.1 lukem restricted to the two-letter codes defined in [ISO3166]). 282 1.1 lukem 283 1.1 lukem 284 1.1 lukem 285 1.1 lukem 286 1.1 lukem Zeilenga Standards Track [Page 5] 287 1.1 lukem 289 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 290 1.1 lukem 291 1.1 lukem 292 1.1 lukem ( 0.9.2342.19200300.100.1.43 NAME 'co' 293 1.1 lukem EQUALITY caseIgnoreMatch 294 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 295 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 296 1.1 lukem 297 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 298 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 299 1.1 lukem in [RFC4517]. 300 1.1 lukem 301 1.1 lukem 2.5. documentAuthor 302 1.1 lukem 303 1.1 lukem The 'documentAuthor' attribute specifies the distinguished names of 304 1.1 lukem authors (or editors) of a document. For example, 305 1.1 lukem 306 1.1 lukem ( 0.9.2342.19200300.100.1.14 NAME 'documentAuthor' 307 1.1 lukem EQUALITY distinguishedNameMatch 308 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 ) 309 1.1 lukem 310 1.1 lukem The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the 311 1.1 lukem 'distinguishedNameMatch' rule are described in [RFC4517]. 312 1.1 lukem 313 1.1 lukem 2.6. documentIdentifier 314 1.1 lukem 315 1.1 lukem The 'documentIdentifier' attribute specifies unique identifiers for a 316 1.1 lukem document. A document may be identified by more than one unique 317 1.1 lukem identifier. For example, RFC 3383 and BCP 64 are unique identifiers 318 1.1 lukem that (presently) refer to the same document. 319 1.1 lukem 320 1.1 lukem ( 0.9.2342.19200300.100.1.11 NAME 'documentIdentifier' 321 1.1 lukem EQUALITY caseIgnoreMatch 322 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 323 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 324 1.1 lukem 325 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 326 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 327 1.1 lukem in [RFC4517]. 328 1.1 lukem 329 1.1 lukem 2.7. documentLocation 330 1.1 lukem 331 1.1 lukem The 'documentLocation' attribute specifies locations of the document 332 1.1 lukem original. 333 1.1 lukem 334 1.1 lukem ( 0.9.2342.19200300.100.1.15 NAME 'documentLocation' 335 1.1 lukem EQUALITY caseIgnoreMatch 336 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 337 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 338 1.1 lukem 339 1.1 lukem 340 1.1 lukem 341 1.1 lukem 342 1.1 lukem 343 1.1 lukem Zeilenga Standards Track [Page 6] 344 1.1 lukem 346 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 347 1.1 lukem 348 1.1 lukem 349 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 350 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 351 1.1 lukem in [RFC4517]. 352 1.1 lukem 353 1.1 lukem 2.8. documentPublisher 354 1.1 lukem 355 1.1 lukem The 'documentPublisher' attribute is the persons and/or organizations 356 1.1 lukem that published the document. Documents that are jointly published 357 1.1 lukem have one value for each publisher. 358 1.1 lukem 359 1.1 lukem ( 0.9.2342.19200300.100.1.56 NAME 'documentPublisher' 360 1.1 lukem EQUALITY caseIgnoreMatch 361 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 362 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 363 1.1 lukem 364 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 365 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 366 1.1 lukem in [RFC4517]. 367 1.1 lukem 368 1.1 lukem 2.9. documentTitle 369 1.1 lukem 370 1.1 lukem The 'documentTitle' attribute specifies the titles of a document. 371 1.1 lukem Multiple values are allowed to accommodate both long and short 372 1.1 lukem titles, or other situations where a document has multiple titles, for 373 1.1 lukem example, "The Lightweight Directory Access Protocol Technical 374 1.1 lukem Specification" and "The LDAP Technical Specification". 375 1.1 lukem 376 1.1 lukem ( 0.9.2342.19200300.100.1.12 NAME 'documentTitle' 377 1.1 lukem EQUALITY caseIgnoreMatch 378 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 379 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 380 1.1 lukem 381 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 382 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 383 1.1 lukem in [RFC4517]. 384 1.1 lukem 385 1.1 lukem 2.10. documentVersion 386 1.1 lukem 387 1.1 lukem The 'documentVersion' attribute specifies the version information of 388 1.1 lukem a document. 389 1.1 lukem 390 1.1 lukem ( 0.9.2342.19200300.100.1.13 NAME 'documentVersion' 391 1.1 lukem EQUALITY caseIgnoreMatch 392 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 393 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 394 1.1 lukem 395 1.1 lukem 396 1.1 lukem 397 1.1 lukem 398 1.1 lukem 399 1.1 lukem 400 1.1 lukem Zeilenga Standards Track [Page 7] 401 1.1 lukem 403 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 404 1.1 lukem 405 1.1 lukem 406 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 407 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 408 1.1 lukem in [RFC4517]. 409 1.1 lukem 410 1.1 lukem 2.11. drink 411 1.1 lukem 412 1.1 lukem The 'drink' (favoriteDrink) attribute specifies the favorite drinks 413 1.1 lukem of an object (or person), for instance, "cola" and "beer". 414 1.1 lukem 415 1.1 lukem ( 0.9.2342.19200300.100.1.5 NAME 'drink' 416 1.1 lukem EQUALITY caseIgnoreMatch 417 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 418 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 419 1.1 lukem 420 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 421 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 422 1.1 lukem in [RFC4517]. 423 1.1 lukem 424 1.1 lukem 2.12. homePhone 425 1.1 lukem 426 1.1 lukem The 'homePhone' (Home Telephone Number) attribute specifies home 427 1.1 lukem telephone numbers (e.g., "+1 775 555 1234") associated with a person. 428 1.1 lukem 429 1.1 lukem ( 0.9.2342.19200300.100.1.20 NAME 'homePhone' 430 1.1 lukem EQUALITY telephoneNumberMatch 431 1.1 lukem SUBSTR telephoneNumberSubstringsMatch 432 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 ) 433 1.1 lukem 434 1.1 lukem The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the 435 1.1 lukem 'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are 436 1.1 lukem described in [RFC4517]. 437 1.1 lukem 438 1.1 lukem 2.13. homePostalAddress 439 1.1 lukem 440 1.1 lukem The 'homePostalAddress' attribute specifies home postal addresses for 441 1.1 lukem an object. Each value should be limited to up to 6 directory strings 442 1.1 lukem of 30 characters each. (Note: It is not intended that the directory 443 1.1 lukem service enforce these limits.) 444 1.1 lukem 445 1.1 lukem ( 0.9.2342.19200300.100.1.39 NAME 'homePostalAddress' 446 1.1 lukem EQUALITY caseIgnoreListMatch 447 1.1 lukem SUBSTR caseIgnoreListSubstringsMatch 448 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.41 ) 449 1.1 lukem 450 1.1 lukem The PostalAddress (1.3.6.1.4.1.1466.115.121.1.41) syntax and the 451 1.1 lukem 'caseIgnoreListMatch' and 'caseIgnoreListSubstringsMatch' rules are 452 1.1 lukem described in [RFC4517]. 453 1.1 lukem 454 1.1 lukem 455 1.1 lukem 456 1.1 lukem 457 1.1 lukem Zeilenga Standards Track [Page 8] 458 1.1 lukem 460 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 461 1.1 lukem 462 1.1 lukem 463 1.1 lukem 2.14. host 464 1.1 lukem 465 1.1 lukem The 'host' attribute specifies host computers, generally by their 466 1.1 lukem primary fully qualified domain name (e.g., my-host.example.com). 467 1.1 lukem 468 1.1 lukem ( 0.9.2342.19200300.100.1.9 NAME 'host' 469 1.1 lukem EQUALITY caseIgnoreMatch 470 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 471 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 472 1.1 lukem 473 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 474 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 475 1.1 lukem in [RFC4517]. 476 1.1 lukem 477 1.1 lukem 2.15. info 478 1.1 lukem 479 1.1 lukem The 'info' attribute specifies any general information pertinent to 480 1.1 lukem an object. This information is not necessarily descriptive of the 481 1.1 lukem object. 482 1.1 lukem 483 1.1 lukem Applications should not attach specific semantics to values of this 484 1.1 lukem attribute. The 'description' attribute [RFC4519] is available for 485 1.1 lukem specifying descriptive information pertinent to an object. 486 1.1 lukem 487 1.1 lukem ( 0.9.2342.19200300.100.1.4 NAME 'info' 488 1.1 lukem EQUALITY caseIgnoreMatch 489 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 490 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{2048} ) 491 1.1 lukem 492 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 493 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 494 1.1 lukem in [RFC4517]. 495 1.1 lukem 496 1.1 lukem 2.16. mail 497 1.1 lukem 498 1.1 lukem The 'mail' (rfc822mailbox) attribute type holds Internet mail 499 1.1 lukem addresses in Mailbox [RFC2821] form (e.g., user (a] example.com). 500 1.1 lukem 501 1.1 lukem ( 0.9.2342.19200300.100.1.3 NAME 'mail' 502 1.1 lukem EQUALITY caseIgnoreIA5Match 503 1.1 lukem SUBSTR caseIgnoreIA5SubstringsMatch 504 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256} ) 505 1.1 lukem 506 1.1 lukem The IA5String (1.3.6.1.4.1.1466.115.121.1.26) syntax and the 507 1.1 lukem 'caseIgnoreIA5Match' and 'caseIgnoreIA5SubstringsMatch' rules are 508 1.1 lukem described in [RFC4517]. 509 1.1 lukem 510 1.1 lukem 511 1.1 lukem 512 1.1 lukem 513 1.1 lukem 514 1.1 lukem Zeilenga Standards Track [Page 9] 515 1.1 lukem 517 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 518 1.1 lukem 519 1.1 lukem 520 1.1 lukem Note that the directory will not ensure that values of this attribute 521 1.1 lukem conform to the <Mailbox> production [RFC2821]. It is the 522 1.1 lukem application's responsibility to ensure that domains it stores in this 523 1.1 lukem attribute are appropriately represented. 524 1.1 lukem 525 1.1 lukem Additionally, the directory will compare values per the matching 526 1.1 lukem rules named in the above attribute type description. As these rules 527 1.1 lukem differ from rules that normally apply to <Mailbox> comparisons, 528 1.1 lukem operational issues may arise. For example, the assertion 529 1.1 lukem (mail=joe (a] example.com) will match "JOE (a] example.com" even though the 530 1.1 lukem <local-parts> differ. Also, where a user has two <Mailbox>es whose 531 1.1 lukem addresses differ only by case of the <local-part>, both cannot be 532 1.1 lukem listed as values of the user's mail attribute (as they are considered 533 1.1 lukem equal by the 'caseIgnoreIA5Match' rule). 534 1.1 lukem 535 1.1 lukem Also note that applications supporting internationalized domain names 536 1.1 lukem SHALL use the ToASCII method [RFC3490] to produce <sub-domain> 537 1.1 lukem components of the <Mailbox> production. 538 1.1 lukem 539 1.1 lukem 2.17. manager 540 1.1 lukem 541 1.1 lukem The 'manager' attribute specifies managers, by distinguished name, of 542 1.1 lukem the person (or entity). 543 1.1 lukem 544 1.1 lukem ( 0.9.2342.19200300.100.1.10 NAME 'manager' 545 1.1 lukem EQUALITY distinguishedNameMatch 546 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 ) 547 1.1 lukem 548 1.1 lukem The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the 549 1.1 lukem 'distinguishedNameMatch' rule are described in [RFC4517]. 550 1.1 lukem 551 1.1 lukem 2.18. mobile 552 1.1 lukem 553 1.1 lukem The 'mobile' (mobileTelephoneNumber) attribute specifies mobile 554 1.1 lukem telephone numbers (e.g., "+1 775 555 6789") associated with a person 555 1.1 lukem (or entity). 556 1.1 lukem 557 1.1 lukem ( 0.9.2342.19200300.100.1.41 NAME 'mobile' 558 1.1 lukem EQUALITY telephoneNumberMatch 559 1.1 lukem SUBSTR telephoneNumberSubstringsMatch 560 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 ) 561 1.1 lukem 562 1.1 lukem The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the 563 1.1 lukem 'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are 564 1.1 lukem described in [RFC4517]. 565 1.1 lukem 566 1.1 lukem 567 1.1 lukem 568 1.1 lukem 569 1.1 lukem 570 1.1 lukem 571 1.1 lukem Zeilenga Standards Track [Page 10] 572 1.1 lukem 574 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 575 1.1 lukem 576 1.1 lukem 577 1.1 lukem 2.19. organizationalStatus 578 1.1 lukem 579 1.1 lukem The 'organizationalStatus' attribute specifies categories by which a 580 1.1 lukem person is often referred to in an organization. Examples of usage in 581 1.1 lukem academia might include "undergraduate student", "researcher", 582 1.1 lukem "professor", and "staff". Multiple values are allowed where the 583 1.1 lukem person is in multiple categories. 584 1.1 lukem 585 1.1 lukem Directory administrators and application designers SHOULD consider 586 1.1 lukem carefully the distinctions between this and the 'title' and 587 1.1 lukem 'userClass' attributes. 588 1.1 lukem 589 1.1 lukem ( 0.9.2342.19200300.100.1.45 NAME 'organizationalStatus' 590 1.1 lukem EQUALITY caseIgnoreMatch 591 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 592 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 593 1.1 lukem 594 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 595 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 596 1.1 lukem in [RFC4517]. 597 1.1 lukem 598 1.1 lukem 2.20. pager 599 1.1 lukem 600 1.1 lukem The 'pager' (pagerTelephoneNumber) attribute specifies pager 601 1.1 lukem telephone numbers (e.g., "+1 775 555 5555") for an object. 602 1.1 lukem 603 1.1 lukem ( 0.9.2342.19200300.100.1.42 NAME 'pager' 604 1.1 lukem EQUALITY telephoneNumberMatch 605 1.1 lukem SUBSTR telephoneNumberSubstringsMatch 606 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 ) 607 1.1 lukem 608 1.1 lukem The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the 609 1.1 lukem 'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are 610 1.1 lukem described in [RFC4517]. 611 1.1 lukem 612 1.1 lukem 2.21. personalTitle 613 1.1 lukem 614 1.1 lukem The 'personalTitle' attribute specifies personal titles for a person. 615 1.1 lukem Examples of personal titles are "Frau", "Dr.", "Herr", and 616 1.1 lukem "Professor". 617 1.1 lukem 618 1.1 lukem ( 0.9.2342.19200300.100.1.40 NAME 'personalTitle' 619 1.1 lukem EQUALITY caseIgnoreMatch 620 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 621 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 622 1.1 lukem 623 1.1 lukem 624 1.1 lukem 625 1.1 lukem 626 1.1 lukem 627 1.1 lukem 628 1.1 lukem Zeilenga Standards Track [Page 11] 629 1.1 lukem 631 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 632 1.1 lukem 633 1.1 lukem 634 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 635 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 636 1.1 lukem in [RFC4517]. 637 1.1 lukem 638 1.1 lukem 2.22. roomNumber 639 1.1 lukem 640 1.1 lukem The 'roomNumber' attribute specifies the room number of an object. 641 1.1 lukem During periods of renumbering, or in other circumstances where a room 642 1.1 lukem has multiple valid room numbers associated with it, multiple values 643 1.1 lukem may be provided. Note that the 'cn' (commonName) attribute type 644 1.1 lukem SHOULD be used for naming room objects. 645 1.1 lukem 646 1.1 lukem ( 0.9.2342.19200300.100.1.6 NAME 'roomNumber' 647 1.1 lukem EQUALITY caseIgnoreMatch 648 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 649 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 650 1.1 lukem 651 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 652 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 653 1.1 lukem in [RFC4517]. 654 1.1 lukem 655 1.1 lukem 2.23. secretary 656 1.1 lukem 657 1.1 lukem The 'secretary' attribute specifies secretaries and/or administrative 658 1.1 lukem assistants, by distinguished name. 659 1.1 lukem 660 1.1 lukem ( 0.9.2342.19200300.100.1.21 NAME 'secretary' 661 1.1 lukem EQUALITY distinguishedNameMatch 662 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 ) 663 1.1 lukem 664 1.1 lukem The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the 665 1.1 lukem 'distinguishedNameMatch' rule are described in [RFC4517]. 666 1.1 lukem 667 1.1 lukem 2.24. uniqueIdentifier 668 1.1 lukem 669 1.1 lukem The 'uniqueIdentifier' attribute specifies a unique identifier for an 670 1.1 lukem object represented in the Directory. The domain within which the 671 1.1 lukem identifier is unique and the exact semantics of the identifier are 672 1.1 lukem for local definition. For a person, this might be an institution- 673 1.1 lukem wide payroll number. For an organizational unit, it might be a 674 1.1 lukem department code. 675 1.1 lukem 676 1.1 lukem ( 0.9.2342.19200300.100.1.44 NAME 'uniqueIdentifier' 677 1.1 lukem EQUALITY caseIgnoreMatch 678 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 679 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 680 1.1 lukem 681 1.1 lukem 682 1.1 lukem 683 1.1 lukem 684 1.1 lukem 685 1.1 lukem Zeilenga Standards Track [Page 12] 686 1.1 lukem 688 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 689 1.1 lukem 690 1.1 lukem 691 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 692 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 693 1.1 lukem in [RFC4517]. 694 1.1 lukem 695 1.1 lukem Note: X.520 also describes an attribute called 'uniqueIdentifier' 696 1.1 lukem (2.5.4.45), which is called 'x500UniqueIdentifier' in LDAP 697 1.1 lukem [RFC4519]. The attribute detailed here ought not be confused 698 1.1 lukem with 'x500UniqueIdentifier'. 699 1.1 lukem 700 1.1 lukem 2.25. userClass 701 1.1 lukem 702 1.1 lukem The 'userClass' attribute specifies categories of computer or 703 1.1 lukem application user. The semantics placed on this attribute are for 704 1.1 lukem local interpretation. Examples of current usage of this attribute in 705 1.1 lukem academia are "student", "staff", and "faculty". Note that the 706 1.1 lukem 'organizationalStatus' attribute type is now often preferred, as it 707 1.1 lukem makes no distinction between persons as opposed to users. 708 1.1 lukem 709 1.1 lukem ( 0.9.2342.19200300.100.1.8 NAME 'userClass' 710 1.1 lukem EQUALITY caseIgnoreMatch 711 1.1 lukem SUBSTR caseIgnoreSubstringsMatch 712 1.1 lukem SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} ) 713 1.1 lukem 714 1.1 lukem The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the 715 1.1 lukem 'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described 716 1.1 lukem in [RFC4517]. 717 1.1 lukem 718 1.1 lukem 3. COSINE Object Classes 719 1.1 lukem 720 1.1 lukem This section details COSINE object classes for use in LDAP. 721 1.1 lukem 722 1.1 lukem 3.1. account 723 1.1 lukem 724 1.1 lukem The 'account' object class is used to define entries representing 725 1.1 lukem computer accounts. The 'uid' attribute SHOULD be used for naming 726 1.1 lukem entries of this object class. 727 1.1 lukem 728 1.1 lukem ( 0.9.2342.19200300.100.4.5 NAME 'account' 729 1.1 lukem SUP top STRUCTURAL 730 1.1 lukem MUST uid 731 1.1 lukem MAY ( description $ seeAlso $ l $ o $ ou $ host ) ) 732 1.1 lukem 733 1.1 lukem The 'top' object class is described in [RFC4512]. The 'description', 734 1.1 lukem 'seeAlso', 'l', 'o', 'ou', and 'uid' attribute types are described in 735 1.1 lukem [RFC4519]. The 'host' attribute type is described in Section 2 of 736 1.1 lukem this document. 737 1.1 lukem 738 1.1 lukem 739 1.1 lukem 740 1.1 lukem 741 1.1 lukem 742 1.1 lukem Zeilenga Standards Track [Page 13] 743 1.1 lukem 745 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 746 1.1 lukem 747 1.1 lukem 748 1.1 lukem 3.3. documentSeriesExample: 749 1.1 lukem 750 1.1 lukem dn: uid=kdz,cn=Accounts,dc=Example,dc=COM 751 1.1 lukem objectClass: account 752 1.1 lukem uid: kdz 753 1.1 lukem seeAlso: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM 754 1.1 lukem 755 1.1 lukem 3.2. document 756 1.1 lukem 757 1.1 lukem The 'document' object class is used to define entries that represent 758 1.1 lukem documents. 759 1.1 lukem 760 1.1 lukem ( 0.9.2342.19200300.100.4.6 NAME 'document' 761 1.1 lukem SUP top STRUCTURAL 762 1.1 lukem MUST documentIdentifier 763 1.1 lukem MAY ( cn $ description $ seeAlso $ l $ o $ ou $ 764 1.1 lukem documentTitle $ documentVersion $ documentAuthor $ 765 1.1 lukem documentLocation $ documentPublisher ) ) 766 1.1 lukem 767 1.1 lukem The 'top' object class is described in [RFC4512]. The 'cn', 768 1.1 lukem 'description', 'seeAlso', 'l', 'o', and 'ou' attribute types are 769 1.1 lukem described in [RFC4519]. The 'documentIdentifier', 'documentTitle', 770 1.1 lukem 'documentVersion', 'documentAuthor', 'documentLocation', and 771 1.1 lukem 'documentPublisher' attribute types are described in Section 2 of 772 1.1 lukem this document. 773 1.1 lukem 774 1.1 lukem Example: 775 1.1 lukem 776 1.1 lukem dn: documentIdentifier=RFC 4524,cn=RFC,dc=Example,dc=COM 777 1.1 lukem objectClass: document 778 1.1 lukem documentIdentifier: RFC 4524 779 1.1 lukem documentTitle: COSINE LDAP/X.500 Schema 780 1.1 lukem documentAuthor: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM 781 1.1 lukem documentLocation: http://www.rfc-editor.org/rfc/rfc4524.txt 782 1.1 lukem documentPublisher: Internet Engineering Task Force 783 1.1 lukem description: A collection of schema elements for use in LDAP 784 1.1 lukem description: Obsoletes RFC 1274 785 1.1 lukem seeAlso: documentIdentifier=RFC 4510,cn=RFC,dc=Example,dc=COM 786 1.1 lukem seeAlso: documentIdentifier=RFC 1274,cn=RFC,dc=Example,dc=COM 787 1.1 lukem 788 1.1 lukem 3.3. documentSeries 789 1.1 lukem 790 1.1 lukem The 'documentSeries' object class is used to define an entry that 791 1.1 lukem represents a series of documents (e.g., The Request For Comments 792 1.1 lukem memos). 793 1.1 lukem 794 1.1 lukem 795 1.1 lukem 796 1.1 lukem 797 1.1 lukem 798 1.1 lukem 799 1.1 lukem Zeilenga Standards Track [Page 14] 800 1.1 lukem 802 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 803 1.1 lukem 804 1.1 lukem 805 1.1 lukem ( 0.9.2342.19200300.100.4.9 NAME 'documentSeries' 806 1.1 lukem SUP top STRUCTURAL 807 1.1 lukem MUST cn 808 1.1 lukem MAY ( description $ l $ o $ ou $ seeAlso $ 809 1.1 lukem telephonenumber ) ) 810 1.1 lukem 811 1.1 lukem The 'top' object class is described in [RFC4512]. The 'description', 812 1.1 lukem 'l', 'o', 'ou', 'seeAlso', and 'telephoneNumber' attribute types are 813 1.1 lukem described in [RFC4519]. 814 1.1 lukem 815 1.1 lukem Example: 816 1.1 lukem 817 1.1 lukem dn: cn=RFC,dc=Example,dc=COM 818 1.1 lukem objectClass: documentSeries 819 1.1 lukem cn: Request for Comments 820 1.1 lukem cn: RFC 821 1.1 lukem description: a series of memos about the Internet 822 1.1 lukem 823 1.1 lukem 3.4. domain 824 1.1 lukem 825 1.1 lukem The 'domain' object class is used to define entries that represent 826 1.1 lukem DNS domains for objects that are not organizations, organizational 827 1.1 lukem units, or other kinds of objects more appropriately defined using an 828 1.1 lukem object class specific to the kind of object being defined (e.g., 829 1.1 lukem 'organization', 'organizationUnit'). 830 1.1 lukem 831 1.1 lukem The 'dc' attribute should be used for naming entries of the 'domain' 832 1.1 lukem object class. 833 1.1 lukem 834 1.1 lukem ( 0.9.2342.19200300.100.4.13 NAME 'domain' 835 1.1 lukem SUP top STRUCTURAL 836 1.1 lukem MUST dc 837 1.1 lukem MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $ 838 1.1 lukem x121Address $ registeredAddress $ destinationIndicator $ 839 1.1 lukem preferredDeliveryMethod $ telexNumber $ 840 1.1 lukem teletexTerminalIdentifier $ telephoneNumber $ 841 1.1 lukem internationaliSDNNumber $ facsimileTelephoneNumber $ street $ 842 1.1 lukem postOfficeBox $ postalCode $ postalAddress $ 843 1.1 lukem physicalDeliveryOfficeName $ st $ l $ description $ o $ 844 1.1 lukem associatedName ) ) 845 1.1 lukem 846 1.1 lukem The 'top' object class and the 'dc', 'userPassword', 'searchGuide', 847 1.1 lukem 'seeAlso', 'businessCategory', 'x121Address', 'registeredAddress', 848 1.1 lukem 'destinationIndicator', 'preferredDeliveryMethod', 'telexNumber', 849 1.1 lukem 'teletexTerminalIdentifier', 'telephoneNumber', 850 1.1 lukem 'internationaliSDNNumber', 'facsimileTelephoneNumber', 'street', 851 1.1 lukem 'postOfficeBox', 'postalCode', 'postalAddress', 852 1.1 lukem 'physicalDeliveryOfficeName', 'st', 'l', 'description', and 'o' types 853 1.1 lukem 854 1.1 lukem 855 1.1 lukem 856 1.1 lukem Zeilenga Standards Track [Page 15] 857 1.1 lukem 859 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 860 1.1 lukem 861 1.1 lukem 862 1.1 lukem are described in [RFC4519]. The 'associatedName' attribute type is 863 1.1 lukem described in Section 2 of this document. 864 1.1 lukem 865 1.1 lukem Example: 866 1.1 lukem 867 1.1 lukem dn: dc=com 868 1.1 lukem objectClass: domain 869 1.1 lukem dc: com 870 1.1 lukem description: the .COM TLD 871 1.1 lukem 872 1.1 lukem 3.5. domainRelatedObject 873 1.1 lukem 874 1.1 lukem The 'domainRelatedObject' object class is used to define entries that 875 1.1 lukem represent DNS domains that are "equivalent" to an X.500 domain, e.g., 876 1.1 lukem an organization or organizational unit. 877 1.1 lukem 878 1.1 lukem ( 0.9.2342.19200300.100.4.17 NAME 'domainRelatedObject' 879 1.1 lukem SUP top AUXILIARY 880 1.1 lukem MUST associatedDomain ) 881 1.1 lukem 882 1.1 lukem The 'top' object class is described in [RFC4512]. The 883 1.1 lukem 'associatedDomain' attribute type is described in Section 2 of this 884 1.1 lukem document. 885 1.1 lukem 886 1.1 lukem Example: 887 1.1 lukem 888 1.1 lukem dn: dc=example,dc=com 889 1.1 lukem objectClass: organization 890 1.1 lukem objectClass: dcObject 891 1.1 lukem objectClass: domainRelatedObject 892 1.1 lukem dc: example 893 1.1 lukem associatedDomain: example.com 894 1.1 lukem o: Example Organization 895 1.1 lukem 896 1.1 lukem The 'organization' and 'dcObject' object classes and the 'dc' and 'o' 897 1.1 lukem attribute types are described in [RFC4519]. 898 1.1 lukem 899 1.1 lukem 3.6. friendlyCountry 900 1.1 lukem 901 1.1 lukem The 'friendlyCountry' object class is used to define entries 902 1.1 lukem representing countries in the DIT. The object class is used to allow 903 1.1 lukem friendlier naming of countries than that allowed by the object class 904 1.1 lukem 'country' [RFC4519]. 905 1.1 lukem 906 1.1 lukem ( 0.9.2342.19200300.100.4.18 NAME 'friendlyCountry' 907 1.1 lukem SUP country STRUCTURAL 908 1.1 lukem MUST co ) 909 1.1 lukem 910 1.1 lukem 911 1.1 lukem 912 1.1 lukem 913 1.1 lukem Zeilenga Standards Track [Page 16] 914 1.1 lukem 916 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 917 1.1 lukem 918 1.1 lukem 919 1.1 lukem The 'country' object class is described in [RFC4519]. The 'co' 920 1.1 lukem attribute type is described in Section 2 of this document. 921 1.1 lukem 922 1.1 lukem Example: 923 1.1 lukem 924 1.1 lukem dn: c=DE 925 1.1 lukem objectClass: country 926 1.1 lukem objectClass: friendlyCountry 927 1.1 lukem c: DE 928 1.1 lukem co: Deutschland 929 1.1 lukem co: Germany 930 1.1 lukem co: Federal Republic of Germany 931 1.1 lukem co: FRG 932 1.1 lukem 933 1.1 lukem The 'c' attribute type is described in [RFC4519]. 934 1.1 lukem 935 1.1 lukem 3.7. rFC822LocalPart 936 1.1 lukem 937 1.1 lukem The 'rFC822LocalPart' object class is used to define entries that 938 1.1 lukem represent the local part of Internet mail addresses [RFC2822]. This 939 1.1 lukem treats the local part of the address as a 'domain' object. 940 1.1 lukem 941 1.1 lukem ( 0.9.2342.19200300.100.4.14 NAME 'rFC822localPart' 942 1.1 lukem SUP domain STRUCTURAL 943 1.1 lukem MAY ( cn $ description $ destinationIndicator $ 944 1.1 lukem facsimileTelephoneNumber $ internationaliSDNNumber $ 945 1.1 lukem physicalDeliveryOfficeName $ postalAddress $ postalCode $ 946 1.1 lukem postOfficeBox $ preferredDeliveryMethod $ registeredAddress $ 947 1.1 lukem seeAlso $ sn $ street $ telephoneNumber $ 948 1.1 lukem teletexTerminalIdentifier $ telexNumber $ x121Address ) ) 949 1.1 lukem 950 1.1 lukem The 'domain' object class is described in Section 3.4 of this 951 1.1 lukem document. The 'cn', 'description', 'destinationIndicator', 952 1.1 lukem 'facsimileTelephoneNumber', 'internationaliSDNNumber, 953 1.1 lukem 'physicalDeliveryOfficeName', 'postalAddress', 'postalCode', 954 1.1 lukem 'postOfficeBox', 'preferredDeliveryMethod', 'registeredAddress', 955 1.1 lukem 'seeAlso', 'sn, 'street', 'telephoneNumber', 956 1.1 lukem 'teletexTerminalIdentifier', 'telexNumber', and 'x121Address' 957 1.1 lukem attribute types are described in [RFC4519]. 958 1.1 lukem 959 1.1 lukem Example: 960 1.1 lukem 961 1.1 lukem dn: dc=kdz,dc=example,dc=com 962 1.1 lukem objectClass: domain 963 1.1 lukem objectClass: rFC822LocalPart 964 1.1 lukem dc: kdz 965 1.1 lukem associatedName: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM 966 1.1 lukem 967 1.1 lukem 968 1.1 lukem 969 1.1 lukem 970 1.1 lukem Zeilenga Standards Track [Page 17] 971 1.1 lukem 973 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 974 1.1 lukem 975 1.1 lukem 976 1.1 lukem The 'dc' attribute type is described in [RFC4519]. 977 1.1 lukem 978 1.1 lukem 3.8. room 979 1.1 lukem 980 1.1 lukem The 'room' object class is used to define entries representing rooms. 981 1.1 lukem The 'cn' (commonName) attribute SHOULD be used for naming entries of 982 1.1 lukem this object class. 983 1.1 lukem 984 1.1 lukem ( 0.9.2342.19200300.100.4.7 NAME 'room' 985 1.1 lukem SUP top STRUCTURAL 986 1.1 lukem MUST cn 987 1.1 lukem MAY ( roomNumber $ description $ seeAlso $ telephoneNumber ) ) 988 1.1 lukem 989 1.1 lukem The 'top' object class is described in [RFC4512]. The 'cn', 990 1.1 lukem 'description', 'seeAlso', and 'telephoneNumber' attribute types are 991 1.1 lukem described in [RFC4519]. The 'roomNumber' attribute type is described 992 1.1 lukem in Section 2 of this document. 993 1.1 lukem 994 1.1 lukem dn: cn=conference room,dc=example,dc=com 995 1.1 lukem objectClass: room 996 1.1 lukem cn: conference room 997 1.1 lukem telephoneNumber: +1 755 555 1111 998 1.1 lukem 999 1.1 lukem 3.9. simpleSecurityObject 1000 1.1 lukem 1001 1.1 lukem The 'simpleSecurityObject' object class is used to require an entry 1002 1.1 lukem to have a 'userPassword' attribute when the entry's structural object 1003 1.1 lukem class does not require (or allow) the 'userPassword attribute'. 1004 1.1 lukem 1005 1.1 lukem ( 0.9.2342.19200300.100.4.19 NAME 'simpleSecurityObject' 1006 1.1 lukem SUP top AUXILIARY 1007 1.1 lukem MUST userPassword ) 1008 1.1 lukem 1009 1.1 lukem The 'top' object class is described in [RFC4512]. The 'userPassword' 1010 1.1 lukem attribute type is described in [RFC4519]. 1011 1.1 lukem 1012 1.1 lukem dn: dc=kdz,dc=Example,dc=COM 1013 1.1 lukem objectClass: account 1014 1.1 lukem objectClass: simpleSecurityObject 1015 1.1 lukem uid: kdz 1016 1.1 lukem userPassword: My Password 1017 1.1 lukem seeAlso: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM 1018 1.1 lukem 1019 1.1 lukem 4. Security Considerations 1020 1.1 lukem 1021 1.1 lukem General LDAP security considerations [RFC4510] are applicable to the 1022 1.1 lukem use of this schema. Additional considerations are noted above where 1023 1.1 lukem appropriate. 1024 1.1 lukem 1025 1.1 lukem 1026 1.1 lukem 1027 1.1 lukem Zeilenga Standards Track [Page 18] 1028 1.1 lukem 1030 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1031 1.1 lukem 1032 1.1 lukem 1033 1.1 lukem Directories administrators should ensure that access to sensitive 1034 1.1 lukem information be restricted to authorized entities and that appropriate 1035 1.1 lukem data security services, including data integrity and data 1036 1.1 lukem confidentiality, are used to protect against eavesdropping. 1037 1.1 lukem 1038 1.1 lukem Simple authentication (e.g., plain text passwords) mechanisms should 1039 1.1 lukem only be used when adequate data security services are in place. LDAP 1040 1.1 lukem offers reasonably strong authentication and data security services 1041 1.1 lukem [RFC4513]. 1042 1.1 lukem 1043 1.1 lukem 5. IANA Considerations 1044 1.1 lukem 1045 1.1 lukem The Internet Assigned Numbers Authority (IANA) has updated the LDAP 1046 1.1 lukem descriptors registry [RFC4520] as indicated in the following 1047 1.1 lukem template: 1048 1.1 lukem 1049 1.1 lukem Subject: Request for LDAP Descriptor Registration Update 1050 1.1 lukem Descriptor (short name): see comment 1051 1.1 lukem Object Identifier: see comments 1052 1.1 lukem Person & email address to contact for further information: 1053 1.1 lukem Kurt Zeilenga <kurt (a] OpenLDAP.org> 1054 1.1 lukem Usage: see comments 1055 1.1 lukem Specification: RFC 4524 1056 1.1 lukem Author/Change Controller: IESG 1057 1.1 lukem Comments: 1058 1.1 lukem 1059 1.1 lukem The following descriptors have been updated to refer to RFC 4524. 1060 1.1 lukem 1061 1.1 lukem NAME Type OID 1062 1.1 lukem ------------------------ ---- -------------------------- 1063 1.1 lukem account O 0.9.2342.19200300.100.4.5 1064 1.1 lukem associatedDomain A 0.9.2342.19200300.100.1.37 1065 1.1 lukem associatedName A 0.9.2342.19200300.100.1.38 1066 1.1 lukem buildingName A 0.9.2342.19200300.100.1.48 1067 1.1 lukem co A 0.9.2342.19200300.100.1.43 1068 1.1 lukem document O 0.9.2342.19200300.100.4.6 1069 1.1 lukem documentAuthor A 0.9.2342.19200300.100.1.14 1070 1.1 lukem documentIdentifier A 0.9.2342.19200300.100.1.11 1071 1.1 lukem documentLocation A 0.9.2342.19200300.100.1.15 1072 1.1 lukem documentPublisher A 0.9.2342.19200300.100.1.56 1073 1.1 lukem documentSeries O 0.9.2342.19200300.100.4.8 1074 1.1 lukem documentTitle A 0.9.2342.19200300.100.1.12 1075 1.1 lukem documentVersion A 0.9.2342.19200300.100.1.13 1076 1.1 lukem domain O 0.9.2342.19200300.100.4.13 1077 1.1 lukem domainRelatedObject O 0.9.2342.19200300.100.4.17 1078 1.1 lukem drink A 0.9.2342.19200300.100.1.5 1079 1.1 lukem favouriteDrink A* 0.9.2342.19200300.100.1.5 1080 1.1 lukem friendlyCountry O 0.9.2342.19200300.100.4.18 1081 1.1 lukem 1082 1.1 lukem 1083 1.1 lukem 1084 1.1 lukem Zeilenga Standards Track [Page 19] 1085 1.1 lukem 1087 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1088 1.1 lukem 1089 1.1 lukem 1090 1.1 lukem friendlyCountryName A* 0.9.2342.19200300.100.1.43 1091 1.1 lukem homePhone A 0.9.2342.19200300.100.1.20 1092 1.1 lukem homePostalAddress A 0.9.2342.19200300.100.1.39 1093 1.1 lukem homeTelephone A* 0.9.2342.19200300.100.1.20 1094 1.1 lukem host A 0.9.2342.19200300.100.1.9 1095 1.1 lukem info A 0.9.2342.19200300.100.1.4 1096 1.1 lukem mail A 0.9.2342.19200300.100.1.3 1097 1.1 lukem manager A 0.9.2342.19200300.100.1.10 1098 1.1 lukem mobile A 0.9.2342.19200300.100.1.41 1099 1.1 lukem mobileTelephoneNumber A* 0.9.2342.19200300.100.1.41 1100 1.1 lukem organizationalStatus A 0.9.2342.19200300.100.1.45 1101 1.1 lukem pager A 0.9.2342.19200300.100.1.42 1102 1.1 lukem pagerTelephoneNumber A* 0.9.2342.19200300.100.1.42 1103 1.1 lukem personalTitle A 0.9.2342.19200300.100.1.40 1104 1.1 lukem rFC822LocalPart O 0.9.2342.19200300.100.4.14 1105 1.1 lukem rfc822Mailbox A* 0.9.2342.19200300.100.1.3 1106 1.1 lukem room O 0.9.2342.19200300.100.4.7 1107 1.1 lukem roomNumber A 0.9.2342.19200300.100.1.6 1108 1.1 lukem secretary A 0.9.2342.19200300.100.1.21 1109 1.1 lukem simpleSecurityObject O 0.9.2342.19200300.100.4.19 1110 1.1 lukem singleLevelQuality A 0.9.2342.19200300.100.1.50 1111 1.1 lukem uniqueIdentifier A 0.9.2342.19200300.100.1.44 1112 1.1 lukem userClass A 0.9.2342.19200300.100.1.8 1113 1.1 lukem 1114 1.1 lukem where Type A is Attribute, Type O is ObjectClass, and * 1115 1.1 lukem indicates that the registration is historic in nature. 1116 1.1 lukem 1117 1.1 lukem 6. Acknowledgements 1118 1.1 lukem 1119 1.1 lukem This document is based on RFC 1274, by Paul Barker and Steve Kille, 1120 1.1 lukem as well as on RFC 2247, by Steve Kill, Mark Wahl, Al Grimstad, Rick 1121 1.1 lukem Huber, and Sri Satulari. 1122 1.1 lukem 1123 1.1 lukem 7. References 1124 1.1 lukem 1125 1.1 lukem 7.1. Normative References 1126 1.1 lukem 1127 1.1 lukem [RFC1034] Mockapetris, P., "Domain names - concepts and 1128 1.1 lukem facilities", STD 13, RFC 1034, November 1987. 1129 1.1 lukem 1130 1.1 lukem [RFC1123] Braden, R., "Requirements for Internet Hosts - 1131 1.1 lukem Application and Support", STD 3, RFC 1123, October 1132 1.1 lukem 1989. 1133 1.1 lukem 1134 1.1 lukem [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate 1135 1.1 lukem Requirement Levels", BCP 14, RFC 2119, March 1997. 1136 1.1 lukem 1137 1.1 lukem 1138 1.1 lukem 1139 1.1 lukem 1140 1.1 lukem 1141 1.1 lukem Zeilenga Standards Track [Page 20] 1142 1.1 lukem 1144 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1145 1.1 lukem 1146 1.1 lukem 1147 1.1 lukem [RFC2181] Elz, R. and R. Bush, "Clarifications to the DNS 1148 1.1 lukem Specification", RFC 2181, July 1997. 1149 1.1 lukem 1150 1.1 lukem [RFC2247] Kille, S., Wahl, M., Grimstad, A., Huber, R., and S. 1151 1.1 lukem Sataluri, "Using Domains in LDAP/X.500 Distinguished 1152 1.1 lukem Names", RFC 2247, January 1998. 1153 1.1 lukem 1154 1.1 lukem [RFC2821] Klensin, J., Ed., "Simple Mail Transfer Protocol", RFC 1155 1.1 lukem 2821, April 2001. 1156 1.1 lukem 1157 1.1 lukem [RFC2822] Resnick, P., "Internet Message Format", RFC 2822, April 1158 1.1 lukem 2001. 1159 1.1 lukem 1160 1.1 lukem [RFC3490] Faltstrom, P., Hoffman, P., and A. Costello, 1161 1.1 lukem "Internationalizing Domain Names in Applications 1162 1.1 lukem (IDNA)", RFC 3490, March 2003. 1163 1.1 lukem 1164 1.1 lukem [RFC4510] Zeilenga, K., Ed., "Lightweight Directory Access 1165 1.1 lukem Protocol (LDAP): Technical Specification Road Map", RFC 1166 1.1 lukem 4510, June 2006. 1167 1.1 lukem 1168 1.1 lukem [RFC4512] Zeilenga, K., "Lightweight Directory Access Protocol 1169 1.1 lukem (LDAP): Directory Information Models", RFC 4512, June 1170 1.1 lukem 2006. 1171 1.1 lukem 1172 1.1 lukem [RFC4513] Harrison, R., "Lightweight Directory Access Protocol 1173 1.1 lukem (LDAP): Authentication Methods and Security 1174 1.1 lukem Mechanisms", RFC 4513, June 2006. 1175 1.1 lukem 1176 1.1 lukem [RFC4517] Legg, S., Ed., "Lightweight Directory Access Protocol 1177 1.1 lukem (LDAP): Syntaxes and Matching Rules", RC 4517, June 1178 1.1 lukem 2006. 1179 1.1 lukem 1180 1.1 lukem [RFC4519] Sciberras, A., Ed., "Lightweight Directory Access 1181 1.1 lukem Protocol (LDAP): Schema for User Applications", RFC 1182 1.1 lukem 4519, June 2006. 1183 1.1 lukem 1184 1.1 lukem [X.501] International Telecommunication Union - 1185 1.1 lukem Telecommunication Standardization Sector, "The 1186 1.1 lukem Directory -- Models," X.501(1993) (also ISO/IEC 9594- 1187 1.1 lukem 2:1994). 1188 1.1 lukem 1189 1.1 lukem 7.2. Informative References 1190 1.1 lukem 1191 1.1 lukem [COSINEpilot] Goodman, D., "PARADISE" section of the March 1991 1192 1.1 lukem INTERNET MONTHLY REPORTS (p. 28-29), 1193 1.1 lukem http://www.iana.org/periodic-reports/imr-mar91.txt 1194 1.1 lukem 1195 1.1 lukem 1196 1.1 lukem 1197 1.1 lukem 1198 1.1 lukem Zeilenga Standards Track [Page 21] 1199 1.1 lukem 1201 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1202 1.1 lukem 1203 1.1 lukem 1204 1.1 lukem [ISO3166] International Organization for Standardization, "Codes 1205 1.1 lukem for the representation of names of countries", ISO 1206 1.1 lukem 3166. 1207 1.1 lukem 1208 1.1 lukem [RFC1274] Barker, P. and S. Kille, "The COSINE and Internet X.500 1209 1.1 lukem Schema", RFC 1274, November 1991. 1210 1.1 lukem 1211 1.1 lukem [RFC1279] Hardcastle-Kille, S., "X.500 and Domains", RFC 1279, 1212 1.1 lukem November 1991. 1213 1.1 lukem 1214 1.1 lukem [RFC1487] Yeong, W., Howes, T., and S. Kille, "X.500 Lightweight 1215 1.1 lukem Directory Access Protocol", RFC 1487, July 1993. 1216 1.1 lukem 1217 1.1 lukem [RFC2251] Wahl, M., Howes, T., and S. Kille, "Lightweight 1218 1.1 lukem Directory Access Protocol (v3)", RFC 2251, December 1219 1.1 lukem 1997. 1220 1.1 lukem 1221 1.1 lukem [RFC2798] Smith, M., "Definition of the inetOrgPerson LDAP Object 1222 1.1 lukem Class", RFC 2798, April 2000. 1223 1.1 lukem 1224 1.1 lukem [RFC3494] Zeilenga, K., "Lightweight Directory Access Protocol 1225 1.1 lukem version 2 (LDAPv2) to Historic Status", RFC 3494, March 1226 1.1 lukem 2003. 1227 1.1 lukem 1228 1.1 lukem [RFC4520] Zeilenga, K., "Internet Assigned Numbers Authority 1229 1.1 lukem (IANA) Considerations for the Lightweight Directory 1230 1.1 lukem Access Protocol (LDAP)", BCP 64, RFC 4520. 1231 1.1 lukem 1232 1.1 lukem 1233 1.1 lukem 1234 1.1 lukem 1235 1.1 lukem 1236 1.1 lukem 1237 1.1 lukem 1238 1.1 lukem 1239 1.1 lukem 1240 1.1 lukem 1241 1.1 lukem 1242 1.1 lukem 1243 1.1 lukem 1244 1.1 lukem 1245 1.1 lukem 1246 1.1 lukem 1247 1.1 lukem 1248 1.1 lukem 1249 1.1 lukem 1250 1.1 lukem 1251 1.1 lukem 1252 1.1 lukem 1253 1.1 lukem 1254 1.1 lukem 1255 1.1 lukem Zeilenga Standards Track [Page 22] 1256 1.1 lukem 1258 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1259 1.1 lukem 1260 1.1 lukem 1261 1.1 lukem Appendix A. Changes since RFC 1274 1262 1.1 lukem 1263 1.1 lukem This document represents a substantial rewrite of RFC 1274. The 1264 1.1 lukem following sections summarize the substantive changes. 1265 1.1 lukem 1266 1.1 lukem A.1. LDAP Short Names 1267 1.1 lukem 1268 1.1 lukem A number of COSINE attribute types have short names in LDAP. 1269 1.1 lukem 1270 1.1 lukem X.500 Name LDAP Short Name 1271 1.1 lukem ------------- --------------- 1272 1.1 lukem domainComponent dc 1273 1.1 lukem favoriteDrink drink 1274 1.1 lukem friendCountryName co 1275 1.1 lukem homeTelephoneNumber homePhone 1276 1.1 lukem mobileTelephoneNumber mobile 1277 1.1 lukem pagerTelephoneNumber pager 1278 1.1 lukem rfc822Mailbox mail 1279 1.1 lukem userid uid 1280 1.1 lukem 1281 1.1 lukem While the LDAP short names are generally used in LDAP, some 1282 1.1 lukem implementations may (for legacy reasons [RFC3494]) recognize the 1283 1.1 lukem attribute type by its X.500 name. Hence, the X.500 names have been 1284 1.1 lukem reserved solely for this purpose. 1285 1.1 lukem 1286 1.1 lukem Note: 'uid' and 'dc' are described in [RFC4519]. 1287 1.1 lukem 1288 1.1 lukem A.2. pilotObject 1289 1.1 lukem 1290 1.1 lukem The 'pilotObject' object class was not brought forward as its 1291 1.1 lukem function is largely replaced by operational attributes introduced in 1292 1.1 lukem X.500(93) [X.501] and version 3 of LDAP [RFC4512]. For instance, the 1293 1.1 lukem function of the 'lastModifiedBy' and 'lastModifiedTime' attribute 1294 1.1 lukem types is now served by the 'creatorsName', 'createTimestamp', 1295 1.1 lukem 'modifiersName', and 'modifyTimestamp' operational attributes 1296 1.1 lukem [RFC4512]. 1297 1.1 lukem 1298 1.1 lukem A.3. pilotPerson 1299 1.1 lukem 1300 1.1 lukem The 'pilotPerson' object class was not brought forward as its 1301 1.1 lukem function is largely replaced by the 'organizationalPerson' [RFC4512] 1302 1.1 lukem object class and its subclasses, such as 'inetOrgPerson' [RFC2798]. 1303 1.1 lukem 1304 1.1 lukem Most of the related attribute types (e.g., 'mail', 'manager') were 1305 1.1 lukem brought forward as they are used in other object classes. 1306 1.1 lukem 1307 1.1 lukem 1308 1.1 lukem 1309 1.1 lukem 1310 1.1 lukem 1311 1.1 lukem 1312 1.1 lukem Zeilenga Standards Track [Page 23] 1313 1.1 lukem 1315 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1316 1.1 lukem 1317 1.1 lukem 1318 1.1 lukem A.4. dNSDomain 1319 1.1 lukem 1320 1.1 lukem The 'dNSDomain' object class and related attribute types were not 1321 1.1 lukem brought forward as its use is primarily experimental [RFC1279]. 1322 1.1 lukem 1323 1.1 lukem A.5. pilotDSA and qualityLabelledData 1324 1.1 lukem 1325 1.1 lukem The 'pilotDSA' and 'qualityLabelledData' object classes, as well as 1326 1.1 lukem related attribute types, were not brought forward as its use is 1327 1.1 lukem primarily experimental [QoS]. 1328 1.1 lukem 1329 1.1 lukem A.6. Attribute Syntaxes 1330 1.1 lukem 1331 1.1 lukem RFC 1274 defined and used caseIgnoreIA5StringSyntax attribute syntax. 1332 1.1 lukem This has been replaced with the IA5String syntax and appropriate 1333 1.1 lukem matching rules in 'mail' and 'associatedDomain'. 1334 1.1 lukem 1335 1.1 lukem RFC 1274 restricted 'mail' to have non-zero length values. This 1336 1.1 lukem restriction is not reflected in the IA5String syntax used in the 1337 1.1 lukem definitions provided in this specification. However, as values are 1338 1.1 lukem to conform to the <Mailbox> production, the 'mail' should not contain 1339 1.1 lukem zero-length values. Unfortunately, the directory service will not 1340 1.1 lukem enforce this restriction. 1341 1.1 lukem 1342 1.1 lukem Appendix B. Changes since RFC 2247 1343 1.1 lukem 1344 1.1 lukem The 'domainNameForm' name form was not brought forward as 1345 1.1 lukem specification of name forms used in LDAP is left to a future 1346 1.1 lukem specification. 1347 1.1 lukem 1348 1.1 lukem Editor's Address 1349 1.1 lukem 1350 1.1 lukem Kurt D. Zeilenga 1351 1.1 lukem OpenLDAP Foundation 1352 1.1 lukem 1353 1.1 lukem EMail: Kurt (a] OpenLDAP.org 1354 1.1 lukem 1355 1.1 lukem 1356 1.1 lukem 1357 1.1 lukem 1358 1.1 lukem 1359 1.1 lukem 1360 1.1 lukem 1361 1.1 lukem 1362 1.1 lukem 1363 1.1 lukem 1364 1.1 lukem 1365 1.1 lukem 1366 1.1 lukem 1367 1.1 lukem 1368 1.1 lukem 1369 1.1 lukem Zeilenga Standards Track [Page 24] 1370 1.1 lukem 1372 1.1 lukem RFC 4524 COSINE LDAP/X.500 Schema June 2006 1373 1.1 lukem 1374 1.1 lukem 1375 1.1 lukem Full Copyright Statement 1376 1.1 lukem 1377 1.1 lukem Copyright (C) The Internet Society (2006). 1378 1.1 lukem 1379 1.1 lukem This document is subject to the rights, licenses and restrictions 1380 1.1 lukem contained in BCP 78, and except as set forth therein, the authors 1381 1.1 lukem retain all their rights. 1382 1.1 lukem 1383 1.1 lukem This document and the information contained herein are provided on an 1384 1.1 lukem "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS 1385 1.1 lukem OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET 1386 1.1 lukem ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, 1387 1.1 lukem INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE 1388 1.1 lukem INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED 1389 1.1 lukem WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. 1390 1.1 lukem 1391 1.1 lukem Intellectual Property 1392 1.1 lukem 1393 1.1 lukem The IETF takes no position regarding the validity or scope of any 1394 1.1 lukem Intellectual Property Rights or other rights that might be claimed to 1395 1.1 lukem pertain to the implementation or use of the technology described in 1396 1.1 lukem this document or the extent to which any license under such rights 1397 1.1 lukem might or might not be available; nor does it represent that it has 1398 1.1 lukem made any independent effort to identify any such rights. Information 1399 1.1 lukem on the procedures with respect to rights in RFC documents can be 1400 1.1 lukem found in BCP 78 and BCP 79. 1401 1.1 lukem 1402 1.1 lukem Copies of IPR disclosures made to the IETF Secretariat and any 1403 1.1 lukem assurances of licenses to be made available, or the result of an 1404 attempt made to obtain a general license or permission for the use of 1405 such proprietary rights by implementers or users of this 1406 specification can be obtained from the IETF on-line IPR repository at 1407 http://www.ietf.org/ipr. 1408 1409 The IETF invites any interested party to bring to its attention any 1410 copyrights, patents or patent applications, or other proprietary 1411 rights that may cover technology that may be required to implement 1412 this standard. Please address the information to the IETF at 1413 ietf-ipr (a] ietf.org. 1414 1415 Acknowledgement 1416 1417 Funding for the RFC Editor function is provided by the IETF 1418 Administrative Support Activity (IASA). 1419 1420 1421 1422 1423 1424 1425 1426 Zeilenga Standards Track [Page 25] 1427 1429