Home | History | Annotate | Line # | Download | only in rfc
      1  1.1  lukem 
      2  1.1  lukem 
      3  1.1  lukem 
      4  1.1  lukem 
      5  1.1  lukem 
      6  1.1  lukem 
      7  1.1  lukem Network Working Group                                   K. Zeilenga, Ed.
      8  1.1  lukem Request for Comments: 4524                           OpenLDAP Foundation
      9  1.1  lukem Obsoletes: 1274                                                June 2006
     10  1.1  lukem Updates: 2247, 2798
     11  1.1  lukem Category: Standards Track
     12  1.1  lukem 
     13  1.1  lukem 
     14  1.1  lukem                         COSINE LDAP/X.500 Schema
     15  1.1  lukem 
     16  1.1  lukem Status of This Memo
     17  1.1  lukem 
     18  1.1  lukem    This document specifies an Internet standards track protocol for the
     19  1.1  lukem    Internet community, and requests discussion and suggestions for
     20  1.1  lukem    improvements.  Please refer to the current edition of the "Internet
     21  1.1  lukem    Official Protocol Standards" (STD 1) for the standardization state
     22  1.1  lukem    and status of this protocol.  Distribution of this memo is unlimited.
     23  1.1  lukem 
     24  1.1  lukem Copyright Notice
     25  1.1  lukem 
     26  1.1  lukem    Copyright (C) The Internet Society (2006).
     27  1.1  lukem 
     28  1.1  lukem Abstract
     29  1.1  lukem 
     30  1.1  lukem    This document provides a collection of schema elements for use with
     31  1.1  lukem    the Lightweight Directory Access Protocol (LDAP) from the COSINE and
     32  1.1  lukem    Internet X.500 pilot projects.
     33  1.1  lukem 
     34  1.1  lukem    This document obsoletes RFC 1274 and updates RFCs 2247 and 2798.
     35  1.1  lukem 
     36  1.1  lukem Table of Contents
     37  1.1  lukem 
     38  1.1  lukem    1. Introduction ....................................................3
     39  1.1  lukem       1.1. Relationship to Other Documents ............................3
     40  1.1  lukem       1.2. Terminology and Conventions ................................4
     41  1.1  lukem    2. COSINE Attribute Types ..........................................4
     42  1.1  lukem       2.1. associatedDomain ...........................................4
     43  1.1  lukem       2.2. associatedName .............................................5
     44  1.1  lukem       2.3. buildingName ...............................................5
     45  1.1  lukem       2.4. co .........................................................5
     46  1.1  lukem       2.5. documentAuthor .............................................6
     47  1.1  lukem       2.6. documentIdentifier .........................................6
     48  1.1  lukem       2.7. documentLocation ...........................................6
     49  1.1  lukem       2.8. documentPublisher ..........................................7
     50  1.1  lukem       2.9. documentTitle ..............................................7
     51  1.1  lukem       2.10. documentVersion ...........................................7
     52  1.1  lukem       2.11. drink .....................................................8
     53  1.1  lukem       2.12. homePhone .................................................8
     54  1.1  lukem       2.13. homePostalAddress .........................................8
     55  1.1  lukem 
     56  1.1  lukem 
     57  1.1  lukem 
     58  1.1  lukem Zeilenga                    Standards Track                     [Page 1]
     59  1.1  lukem 
     61  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
     62  1.1  lukem 
     63  1.1  lukem 
     64  1.1  lukem       2.14. host ......................................................9
     65  1.1  lukem       2.15. info ......................................................9
     66  1.1  lukem       2.16. mail ......................................................9
     67  1.1  lukem       2.17. manager ..................................................10
     68  1.1  lukem       2.18. mobile ...................................................10
     69  1.1  lukem       2.19. organizationalStatus .....................................11
     70  1.1  lukem       2.20. pager ....................................................11
     71  1.1  lukem       2.21. personalTitle ............................................11
     72  1.1  lukem       2.22. roomNumber ...............................................12
     73  1.1  lukem       2.23. secretary ................................................12
     74  1.1  lukem       2.24. uniqueIdentifier .........................................12
     75  1.1  lukem       2.25. userClass ................................................13
     76  1.1  lukem    3. COSINE Object Classes ..........................................13
     77  1.1  lukem       3.1. account ...................................................13
     78  1.1  lukem       3.2. document ..................................................14
     79  1.1  lukem       3.3. documentSeries ............................................14
     80  1.1  lukem       3.4. domain ....................................................15
     81  1.1  lukem       3.5. domainRelatedObject .......................................16
     82  1.1  lukem       3.6. friendlyCountry ...........................................16
     83  1.1  lukem       3.7. rFC822LocalPart ...........................................17
     84  1.1  lukem       3.8. room ......................................................18
     85  1.1  lukem       3.9. simpleSecurityObject ......................................18
     86  1.1  lukem    4. Security Considerations ........................................18
     87  1.1  lukem    5. IANA Considerations ............................................19
     88  1.1  lukem    6. Acknowledgements ...............................................20
     89  1.1  lukem    7. References .....................................................20
     90  1.1  lukem       7.1. Normative References ......................................20
     91  1.1  lukem       7.2. Informative References ....................................21
     92  1.1  lukem    Appendix A.  Changes since RFC 1274 ...............................23
     93  1.1  lukem       A.1.  LDAP Short Names .........................................23
     94  1.1  lukem       A.2.  pilotObject ..............................................23
     95  1.1  lukem       A.3.  pilotPerson ..............................................23
     96  1.1  lukem       A.4.  dNSDomain ................................................24
     97  1.1  lukem       A.5.  pilotDSA and qualityLabelledData .........................24
     98  1.1  lukem       A.6.  Attribute Syntaxes .......................................24
     99  1.1  lukem    Appendix B.  Changes since RFC 2247 ...............................24
    100  1.1  lukem 
    101  1.1  lukem 
    102  1.1  lukem 
    103  1.1  lukem 
    104  1.1  lukem 
    105  1.1  lukem 
    106  1.1  lukem 
    107  1.1  lukem 
    108  1.1  lukem 
    109  1.1  lukem 
    110  1.1  lukem 
    111  1.1  lukem 
    112  1.1  lukem 
    113  1.1  lukem 
    114  1.1  lukem 
    115  1.1  lukem Zeilenga                    Standards Track                     [Page 2]
    116  1.1  lukem 
    118  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    119  1.1  lukem 
    120  1.1  lukem 
    121  1.1  lukem 1.  Introduction
    122  1.1  lukem 
    123  1.1  lukem    In the late 1980s, X.500 Directory Services were standardized by the
    124  1.1  lukem    CCITT (Commite' Consultatif International de Telegraphique et
    125  1.1  lukem    Telephonique), now a part of the ITU (International Telephone Union).
    126  1.1  lukem    This lead to Directory Service piloting activities in the early
    127  1.1  lukem    1990s, including the COSINE (Co-operation and Open Systems
    128  1.1  lukem    Interconnection in Europe) PARADISE Project pilot [COSINEpilot] in
    129  1.1  lukem    Europe.  Motivated by needs for large-scale directory pilots, RFC
    130  1.1  lukem    1274 was published to standardize the directory schema and naming
    131  1.1  lukem    architecture for use in the COSINE and other Internet X.500 pilots
    132  1.1  lukem    [RFC1274].
    133  1.1  lukem 
    134  1.1  lukem    In the years that followed, X.500 Directory Services have evolved to
    135  1.1  lukem    incorporate new capabilities and even new protocols.  In particular,
    136  1.1  lukem    the Lightweight Directory Access Protocol (LDAP) [RFC4510] was
    137  1.1  lukem    introduced in the early 1990s [RFC1487], with Version 3 of LDAP
    138  1.1  lukem    introduced in the late 1990s [RFC2251] and subsequently revised in
    139  1.1  lukem    2005 [RFC4510].
    140  1.1  lukem 
    141  1.1  lukem    While much of the material in RFC 1274 has been superceded by
    142  1.1  lukem    subsequently published ITU-T Recommendations and IETF RFCs, many of
    143  1.1  lukem    the schema elements lack standardized schema descriptions for use in
    144  1.1  lukem    modern X.500 and LDAP directory services despite the fact that these
    145  1.1  lukem    schema elements are in wide use today.  As the old schema
    146  1.1  lukem    descriptions cannot be used without adaptation, interoperability
    147  1.1  lukem    issues may arise due to lack of standardized modern schema
    148  1.1  lukem    descriptions.
    149  1.1  lukem 
    150  1.1  lukem    This document addresses these issues by offering standardized schema
    151  1.1  lukem    descriptions, where needed, for widely used COSINE schema elements.
    152  1.1  lukem 
    153  1.1  lukem 1.1.  Relationship to Other Documents
    154  1.1  lukem 
    155  1.1  lukem    This document, together with [RFC4519] and [RFC4517], obsoletes RFC
    156  1.1  lukem    1274 in its entirety.  [RFC4519] replaces Sections 9.3.1 (Userid) and
    157  1.1  lukem    9.3.21 (Domain Component) of RFC 1274.  [RFC4517] replaces Section
    158  1.1  lukem    9.4 (Generally useful syntaxes) of RFC 1274.
    159  1.1  lukem 
    160  1.1  lukem    This document replaces the remainder of RFC 1274.  Appendix A
    161  1.1  lukem    discusses changes since RFC 1274, as well as why certain schema
    162  1.1  lukem    elements were not brought forward in this revision of the COSINE
    163  1.1  lukem    schema.  All elements not brought are to be regarded as Historic.
    164  1.1  lukem 
    165  1.1  lukem    The description of the 'domain' object class provided in this
    166  1.1  lukem    document supercedes that found in RFC 2247.  That is, Section 3.4 of
    167  1.1  lukem    this document replaces Section 5.2 of [RFC2247].
    168  1.1  lukem 
    169  1.1  lukem 
    170  1.1  lukem 
    171  1.1  lukem 
    172  1.1  lukem Zeilenga                    Standards Track                     [Page 3]
    173  1.1  lukem 
    175  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    176  1.1  lukem 
    177  1.1  lukem 
    178  1.1  lukem    Some of the schema elements specified here were described in RFC 2798
    179  1.1  lukem    (inetOrgPerson schema).  This document supersedes these descriptions.
    180  1.1  lukem    This document, together with [RFC4519], replaces Section 9.1.3 of RFC
    181  1.1  lukem    2798.
    182  1.1  lukem 
    183  1.1  lukem 1.2.  Terminology and Conventions
    184  1.1  lukem 
    185  1.1  lukem    The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
    186  1.1  lukem    "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
    187  1.1  lukem    document are to be interpreted as described in BCP 14 [RFC2119].
    188  1.1  lukem 
    189  1.1  lukem    DIT stands for Directory Information Tree.
    190  1.1  lukem    DN stands for Distinguished Name.
    191  1.1  lukem    DSA stands for Directory System Agent, a server.
    192  1.1  lukem    DSE stands for DSA-Specific Entry.
    193  1.1  lukem    DUA stands for Directory User Agent, a client.
    194  1.1  lukem 
    195  1.1  lukem    These terms are discussed in [RFC4512].
    196  1.1  lukem 
    197  1.1  lukem    Schema definitions are provided using LDAP description formats
    198  1.1  lukem    [RFC4512].  Definitions provided here are formatted (line wrapped)
    199  1.1  lukem    for readability.
    200  1.1  lukem 
    201  1.1  lukem 2.  COSINE Attribute Types
    202  1.1  lukem 
    203  1.1  lukem    This section details COSINE attribute types for use in LDAP.
    204  1.1  lukem 
    205  1.1  lukem 2.1.  associatedDomain
    206  1.1  lukem 
    207  1.1  lukem    The 'associatedDomain' attribute specifies DNS [RFC1034][RFC2181]
    208  1.1  lukem    host names [RFC1123] that are associated with an object.   That is,
    209  1.1  lukem    values of this attribute should conform to the following ABNF:
    210  1.1  lukem 
    211  1.1  lukem     domain = root / label *( DOT label )
    212  1.1  lukem     root   = SPACE
    213  1.1  lukem     label  = LETDIG [ *61( LETDIG / HYPHEN ) LETDIG ]
    214  1.1  lukem     LETDIG = %x30-39 / %x41-5A / %x61-7A ; "0" - "9" / "A"-"Z" / "a"-"z"
    215  1.1  lukem     SPACE  = %x20                        ; space (" ")
    216  1.1  lukem     HYPHEN = %x2D                        ; hyphen ("-")
    217  1.1  lukem     DOT    = %x2E                        ; period (".")
    218  1.1  lukem 
    219  1.1  lukem    For example, the entry in the DIT with a DN <DC=example,DC=com> might
    220  1.1  lukem    have an associated domain of "example.com".
    221  1.1  lukem 
    222  1.1  lukem       ( 0.9.2342.19200300.100.1.37 NAME 'associatedDomain'
    223  1.1  lukem         EQUALITY caseIgnoreIA5Match
    224  1.1  lukem         SUBSTR caseIgnoreIA5SubstringsMatch
    225  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
    226  1.1  lukem 
    227  1.1  lukem 
    228  1.1  lukem 
    229  1.1  lukem Zeilenga                    Standards Track                     [Page 4]
    230  1.1  lukem 
    232  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    233  1.1  lukem 
    234  1.1  lukem 
    235  1.1  lukem    The IA5String (1.3.6.1.4.1.1466.115.121.1.26) syntax and the
    236  1.1  lukem    'caseIgnoreIA5Match' and 'caseIgnoreIA5SubstringsMatch' rules are
    237  1.1  lukem    described in [RFC4517].
    238  1.1  lukem 
    239  1.1  lukem    Note that the directory will not ensure that values of this attribute
    240  1.1  lukem    conform to the <domain> production provided above.  It is the
    241  1.1  lukem    application's responsibility to ensure that domains it stores in this
    242  1.1  lukem    attribute are appropriately represented.
    243  1.1  lukem 
    244  1.1  lukem    Also note that applications supporting Internationalized Domain Names
    245  1.1  lukem    SHALL use the ToASCII method [RFC3490] to produce <label> components
    246  1.1  lukem    of the <domain> production.
    247  1.1  lukem 
    248  1.1  lukem 2.2.  associatedName
    249  1.1  lukem 
    250  1.1  lukem    The 'associatedName' attribute specifies names of entries in the
    251  1.1  lukem    organizational DIT associated with a DNS domain [RFC1034][RFC2181].
    252  1.1  lukem 
    253  1.1  lukem       ( 0.9.2342.19200300.100.1.38 NAME 'associatedName'
    254  1.1  lukem         EQUALITY distinguishedNameMatch
    255  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
    256  1.1  lukem 
    257  1.1  lukem    The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the
    258  1.1  lukem    'distinguishedNameMatch' rule are described in [RFC4517].
    259  1.1  lukem 
    260  1.1  lukem 2.3.  buildingName
    261  1.1  lukem 
    262  1.1  lukem    The 'buildingName' attribute specifies names of the buildings where
    263  1.1  lukem    an organization or organizational unit is based, for example, "The
    264  1.1  lukem    White House".
    265  1.1  lukem 
    266  1.1  lukem       ( 0.9.2342.19200300.100.1.48 NAME 'buildingName'
    267  1.1  lukem         EQUALITY caseIgnoreMatch
    268  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    269  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    270  1.1  lukem 
    271  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    272  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    273  1.1  lukem    in [RFC4517].
    274  1.1  lukem 
    275  1.1  lukem 2.4.  co
    276  1.1  lukem 
    277  1.1  lukem    The 'co' (Friendly Country Name) attribute specifies names of
    278  1.1  lukem    countries in human-readable format, for example, "Germany" and
    279  1.1  lukem    "Federal Republic of Germany".  It is commonly used in conjunction
    280  1.1  lukem    with the 'c' (Country Name) [RFC4519] attribute (whose values are
    281  1.1  lukem    restricted to the two-letter codes defined in [ISO3166]).
    282  1.1  lukem 
    283  1.1  lukem 
    284  1.1  lukem 
    285  1.1  lukem 
    286  1.1  lukem Zeilenga                    Standards Track                     [Page 5]
    287  1.1  lukem 
    289  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    290  1.1  lukem 
    291  1.1  lukem 
    292  1.1  lukem       ( 0.9.2342.19200300.100.1.43 NAME 'co'
    293  1.1  lukem         EQUALITY caseIgnoreMatch
    294  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    295  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
    296  1.1  lukem 
    297  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    298  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    299  1.1  lukem    in [RFC4517].
    300  1.1  lukem 
    301  1.1  lukem 2.5.  documentAuthor
    302  1.1  lukem 
    303  1.1  lukem    The 'documentAuthor' attribute specifies the distinguished names of
    304  1.1  lukem    authors (or editors) of a document.  For example,
    305  1.1  lukem 
    306  1.1  lukem       ( 0.9.2342.19200300.100.1.14 NAME 'documentAuthor'
    307  1.1  lukem         EQUALITY distinguishedNameMatch
    308  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
    309  1.1  lukem 
    310  1.1  lukem    The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the
    311  1.1  lukem    'distinguishedNameMatch' rule are described in [RFC4517].
    312  1.1  lukem 
    313  1.1  lukem 2.6.  documentIdentifier
    314  1.1  lukem 
    315  1.1  lukem    The 'documentIdentifier' attribute specifies unique identifiers for a
    316  1.1  lukem    document.  A document may be identified by more than one unique
    317  1.1  lukem    identifier.  For example, RFC 3383 and BCP 64 are unique identifiers
    318  1.1  lukem    that (presently) refer to the same document.
    319  1.1  lukem 
    320  1.1  lukem       ( 0.9.2342.19200300.100.1.11 NAME 'documentIdentifier'
    321  1.1  lukem         EQUALITY caseIgnoreMatch
    322  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    323  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    324  1.1  lukem 
    325  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    326  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    327  1.1  lukem    in [RFC4517].
    328  1.1  lukem 
    329  1.1  lukem 2.7.  documentLocation
    330  1.1  lukem 
    331  1.1  lukem    The 'documentLocation' attribute specifies locations of the document
    332  1.1  lukem    original.
    333  1.1  lukem 
    334  1.1  lukem       ( 0.9.2342.19200300.100.1.15 NAME 'documentLocation'
    335  1.1  lukem         EQUALITY caseIgnoreMatch
    336  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    337  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    338  1.1  lukem 
    339  1.1  lukem 
    340  1.1  lukem 
    341  1.1  lukem 
    342  1.1  lukem 
    343  1.1  lukem Zeilenga                    Standards Track                     [Page 6]
    344  1.1  lukem 
    346  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    347  1.1  lukem 
    348  1.1  lukem 
    349  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    350  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    351  1.1  lukem    in [RFC4517].
    352  1.1  lukem 
    353  1.1  lukem 2.8.  documentPublisher
    354  1.1  lukem 
    355  1.1  lukem    The 'documentPublisher' attribute is the persons and/or organizations
    356  1.1  lukem    that published the document.  Documents that are jointly published
    357  1.1  lukem    have one value for each publisher.
    358  1.1  lukem 
    359  1.1  lukem       ( 0.9.2342.19200300.100.1.56 NAME 'documentPublisher'
    360  1.1  lukem         EQUALITY caseIgnoreMatch
    361  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    362  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
    363  1.1  lukem 
    364  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    365  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    366  1.1  lukem    in [RFC4517].
    367  1.1  lukem 
    368  1.1  lukem 2.9.  documentTitle
    369  1.1  lukem 
    370  1.1  lukem    The 'documentTitle' attribute specifies the titles of a document.
    371  1.1  lukem    Multiple values are allowed to accommodate both long and short
    372  1.1  lukem    titles, or other situations where a document has multiple titles, for
    373  1.1  lukem    example, "The Lightweight Directory Access Protocol Technical
    374  1.1  lukem    Specification" and "The LDAP Technical Specification".
    375  1.1  lukem 
    376  1.1  lukem       ( 0.9.2342.19200300.100.1.12 NAME 'documentTitle'
    377  1.1  lukem         EQUALITY caseIgnoreMatch
    378  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    379  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    380  1.1  lukem 
    381  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    382  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    383  1.1  lukem    in [RFC4517].
    384  1.1  lukem 
    385  1.1  lukem 2.10.  documentVersion
    386  1.1  lukem 
    387  1.1  lukem    The 'documentVersion' attribute specifies the version information of
    388  1.1  lukem    a document.
    389  1.1  lukem 
    390  1.1  lukem       ( 0.9.2342.19200300.100.1.13 NAME 'documentVersion'
    391  1.1  lukem         EQUALITY caseIgnoreMatch
    392  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    393  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    394  1.1  lukem 
    395  1.1  lukem 
    396  1.1  lukem 
    397  1.1  lukem 
    398  1.1  lukem 
    399  1.1  lukem 
    400  1.1  lukem Zeilenga                    Standards Track                     [Page 7]
    401  1.1  lukem 
    403  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    404  1.1  lukem 
    405  1.1  lukem 
    406  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    407  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    408  1.1  lukem    in [RFC4517].
    409  1.1  lukem 
    410  1.1  lukem 2.11.  drink
    411  1.1  lukem 
    412  1.1  lukem    The 'drink' (favoriteDrink) attribute specifies the favorite drinks
    413  1.1  lukem    of an object (or person), for instance, "cola" and "beer".
    414  1.1  lukem 
    415  1.1  lukem       ( 0.9.2342.19200300.100.1.5 NAME 'drink'
    416  1.1  lukem         EQUALITY caseIgnoreMatch
    417  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    418  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    419  1.1  lukem 
    420  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    421  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    422  1.1  lukem    in [RFC4517].
    423  1.1  lukem 
    424  1.1  lukem 2.12.  homePhone
    425  1.1  lukem 
    426  1.1  lukem    The 'homePhone' (Home Telephone Number) attribute specifies home
    427  1.1  lukem    telephone numbers (e.g., "+1 775 555 1234") associated with a person.
    428  1.1  lukem 
    429  1.1  lukem       ( 0.9.2342.19200300.100.1.20 NAME 'homePhone'
    430  1.1  lukem         EQUALITY telephoneNumberMatch
    431  1.1  lukem         SUBSTR telephoneNumberSubstringsMatch
    432  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
    433  1.1  lukem 
    434  1.1  lukem    The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the
    435  1.1  lukem    'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are
    436  1.1  lukem    described in [RFC4517].
    437  1.1  lukem 
    438  1.1  lukem 2.13.  homePostalAddress
    439  1.1  lukem 
    440  1.1  lukem    The 'homePostalAddress' attribute specifies home postal addresses for
    441  1.1  lukem    an object.  Each value should be limited to up to 6 directory strings
    442  1.1  lukem    of 30 characters each.  (Note: It is not intended that the directory
    443  1.1  lukem    service enforce these limits.)
    444  1.1  lukem 
    445  1.1  lukem       ( 0.9.2342.19200300.100.1.39 NAME 'homePostalAddress'
    446  1.1  lukem         EQUALITY caseIgnoreListMatch
    447  1.1  lukem         SUBSTR caseIgnoreListSubstringsMatch
    448  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.41 )
    449  1.1  lukem 
    450  1.1  lukem    The PostalAddress (1.3.6.1.4.1.1466.115.121.1.41) syntax and the
    451  1.1  lukem    'caseIgnoreListMatch' and 'caseIgnoreListSubstringsMatch' rules are
    452  1.1  lukem    described in [RFC4517].
    453  1.1  lukem 
    454  1.1  lukem 
    455  1.1  lukem 
    456  1.1  lukem 
    457  1.1  lukem Zeilenga                    Standards Track                     [Page 8]
    458  1.1  lukem 
    460  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    461  1.1  lukem 
    462  1.1  lukem 
    463  1.1  lukem 2.14.  host
    464  1.1  lukem 
    465  1.1  lukem    The 'host' attribute specifies host computers, generally by their
    466  1.1  lukem    primary fully qualified domain name (e.g., my-host.example.com).
    467  1.1  lukem 
    468  1.1  lukem       ( 0.9.2342.19200300.100.1.9 NAME 'host'
    469  1.1  lukem         EQUALITY caseIgnoreMatch
    470  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    471  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    472  1.1  lukem 
    473  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    474  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    475  1.1  lukem    in [RFC4517].
    476  1.1  lukem 
    477  1.1  lukem 2.15.  info
    478  1.1  lukem 
    479  1.1  lukem    The 'info' attribute specifies any general information pertinent to
    480  1.1  lukem    an object.  This information is not necessarily descriptive of the
    481  1.1  lukem    object.
    482  1.1  lukem 
    483  1.1  lukem    Applications should not attach specific semantics to values of this
    484  1.1  lukem    attribute.  The 'description' attribute [RFC4519] is available for
    485  1.1  lukem    specifying descriptive information pertinent to an object.
    486  1.1  lukem 
    487  1.1  lukem       ( 0.9.2342.19200300.100.1.4 NAME 'info'
    488  1.1  lukem         EQUALITY caseIgnoreMatch
    489  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    490  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{2048} )
    491  1.1  lukem 
    492  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    493  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    494  1.1  lukem    in [RFC4517].
    495  1.1  lukem 
    496  1.1  lukem 2.16.  mail
    497  1.1  lukem 
    498  1.1  lukem    The 'mail' (rfc822mailbox) attribute type holds Internet mail
    499  1.1  lukem    addresses in Mailbox [RFC2821] form (e.g., user (a] example.com).
    500  1.1  lukem 
    501  1.1  lukem       ( 0.9.2342.19200300.100.1.3 NAME 'mail'
    502  1.1  lukem         EQUALITY caseIgnoreIA5Match
    503  1.1  lukem         SUBSTR caseIgnoreIA5SubstringsMatch
    504  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256} )
    505  1.1  lukem 
    506  1.1  lukem    The IA5String (1.3.6.1.4.1.1466.115.121.1.26) syntax and the
    507  1.1  lukem    'caseIgnoreIA5Match' and 'caseIgnoreIA5SubstringsMatch' rules are
    508  1.1  lukem    described in [RFC4517].
    509  1.1  lukem 
    510  1.1  lukem 
    511  1.1  lukem 
    512  1.1  lukem 
    513  1.1  lukem 
    514  1.1  lukem Zeilenga                    Standards Track                     [Page 9]
    515  1.1  lukem 
    517  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    518  1.1  lukem 
    519  1.1  lukem 
    520  1.1  lukem    Note that the directory will not ensure that values of this attribute
    521  1.1  lukem    conform to the <Mailbox> production [RFC2821].  It is the
    522  1.1  lukem    application's responsibility to ensure that domains it stores in this
    523  1.1  lukem    attribute are appropriately represented.
    524  1.1  lukem 
    525  1.1  lukem    Additionally, the directory will compare values per the matching
    526  1.1  lukem    rules named in the above attribute type description.  As these rules
    527  1.1  lukem    differ from rules that normally apply to <Mailbox> comparisons,
    528  1.1  lukem    operational issues may arise.  For example, the assertion
    529  1.1  lukem    (mail=joe (a] example.com) will match "JOE (a] example.com" even though the
    530  1.1  lukem    <local-parts> differ.  Also, where a user has two <Mailbox>es whose
    531  1.1  lukem    addresses differ only by case of the <local-part>, both cannot be
    532  1.1  lukem    listed as values of the user's mail attribute (as they are considered
    533  1.1  lukem    equal by the 'caseIgnoreIA5Match' rule).
    534  1.1  lukem 
    535  1.1  lukem    Also note that applications supporting internationalized domain names
    536  1.1  lukem    SHALL use the ToASCII method [RFC3490] to produce <sub-domain>
    537  1.1  lukem    components of the <Mailbox> production.
    538  1.1  lukem 
    539  1.1  lukem 2.17.  manager
    540  1.1  lukem 
    541  1.1  lukem    The 'manager' attribute specifies managers, by distinguished name, of
    542  1.1  lukem    the person (or entity).
    543  1.1  lukem 
    544  1.1  lukem       ( 0.9.2342.19200300.100.1.10 NAME 'manager'
    545  1.1  lukem         EQUALITY distinguishedNameMatch
    546  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
    547  1.1  lukem 
    548  1.1  lukem    The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the
    549  1.1  lukem    'distinguishedNameMatch' rule are described in [RFC4517].
    550  1.1  lukem 
    551  1.1  lukem 2.18.  mobile
    552  1.1  lukem 
    553  1.1  lukem    The 'mobile' (mobileTelephoneNumber) attribute specifies mobile
    554  1.1  lukem    telephone numbers (e.g., "+1 775 555 6789") associated with a person
    555  1.1  lukem    (or entity).
    556  1.1  lukem 
    557  1.1  lukem       ( 0.9.2342.19200300.100.1.41 NAME 'mobile'
    558  1.1  lukem         EQUALITY telephoneNumberMatch
    559  1.1  lukem         SUBSTR telephoneNumberSubstringsMatch
    560  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
    561  1.1  lukem 
    562  1.1  lukem    The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the
    563  1.1  lukem    'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are
    564  1.1  lukem    described in [RFC4517].
    565  1.1  lukem 
    566  1.1  lukem 
    567  1.1  lukem 
    568  1.1  lukem 
    569  1.1  lukem 
    570  1.1  lukem 
    571  1.1  lukem Zeilenga                    Standards Track                    [Page 10]
    572  1.1  lukem 
    574  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    575  1.1  lukem 
    576  1.1  lukem 
    577  1.1  lukem 2.19.  organizationalStatus
    578  1.1  lukem 
    579  1.1  lukem    The 'organizationalStatus' attribute specifies categories by which a
    580  1.1  lukem    person is often referred to in an organization.  Examples of usage in
    581  1.1  lukem    academia might include "undergraduate student", "researcher",
    582  1.1  lukem    "professor", and "staff".  Multiple values are allowed where the
    583  1.1  lukem    person is in multiple categories.
    584  1.1  lukem 
    585  1.1  lukem    Directory administrators and application designers SHOULD consider
    586  1.1  lukem    carefully the distinctions between this and the 'title' and
    587  1.1  lukem    'userClass' attributes.
    588  1.1  lukem 
    589  1.1  lukem       ( 0.9.2342.19200300.100.1.45 NAME 'organizationalStatus'
    590  1.1  lukem         EQUALITY caseIgnoreMatch
    591  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    592  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    593  1.1  lukem 
    594  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    595  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    596  1.1  lukem    in [RFC4517].
    597  1.1  lukem 
    598  1.1  lukem 2.20.  pager
    599  1.1  lukem 
    600  1.1  lukem    The 'pager' (pagerTelephoneNumber) attribute specifies pager
    601  1.1  lukem    telephone numbers (e.g., "+1 775 555 5555") for an object.
    602  1.1  lukem 
    603  1.1  lukem       ( 0.9.2342.19200300.100.1.42 NAME 'pager'
    604  1.1  lukem         EQUALITY telephoneNumberMatch
    605  1.1  lukem         SUBSTR telephoneNumberSubstringsMatch
    606  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
    607  1.1  lukem 
    608  1.1  lukem    The telephoneNumber (1.3.6.1.4.1.1466.115.121.1.50) syntax and the
    609  1.1  lukem    'telephoneNumberMatch' and 'telephoneNumberSubstringsMatch' rules are
    610  1.1  lukem    described in [RFC4517].
    611  1.1  lukem 
    612  1.1  lukem 2.21.  personalTitle
    613  1.1  lukem 
    614  1.1  lukem    The 'personalTitle' attribute specifies personal titles for a person.
    615  1.1  lukem    Examples of personal titles are "Frau", "Dr.", "Herr", and
    616  1.1  lukem    "Professor".
    617  1.1  lukem 
    618  1.1  lukem       ( 0.9.2342.19200300.100.1.40 NAME 'personalTitle'
    619  1.1  lukem         EQUALITY caseIgnoreMatch
    620  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    621  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    622  1.1  lukem 
    623  1.1  lukem 
    624  1.1  lukem 
    625  1.1  lukem 
    626  1.1  lukem 
    627  1.1  lukem 
    628  1.1  lukem Zeilenga                    Standards Track                    [Page 11]
    629  1.1  lukem 
    631  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    632  1.1  lukem 
    633  1.1  lukem 
    634  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    635  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    636  1.1  lukem    in [RFC4517].
    637  1.1  lukem 
    638  1.1  lukem 2.22.  roomNumber
    639  1.1  lukem 
    640  1.1  lukem    The 'roomNumber' attribute specifies the room number of an object.
    641  1.1  lukem    During periods of renumbering, or in other circumstances where a room
    642  1.1  lukem    has multiple valid room numbers associated with it, multiple values
    643  1.1  lukem    may be provided.  Note that the 'cn' (commonName) attribute type
    644  1.1  lukem    SHOULD be used for naming room objects.
    645  1.1  lukem 
    646  1.1  lukem       ( 0.9.2342.19200300.100.1.6 NAME 'roomNumber'
    647  1.1  lukem         EQUALITY caseIgnoreMatch
    648  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    649  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    650  1.1  lukem 
    651  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    652  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    653  1.1  lukem    in [RFC4517].
    654  1.1  lukem 
    655  1.1  lukem 2.23.  secretary
    656  1.1  lukem 
    657  1.1  lukem    The 'secretary' attribute specifies secretaries and/or administrative
    658  1.1  lukem    assistants, by distinguished name.
    659  1.1  lukem 
    660  1.1  lukem       ( 0.9.2342.19200300.100.1.21 NAME 'secretary'
    661  1.1  lukem         EQUALITY distinguishedNameMatch
    662  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
    663  1.1  lukem 
    664  1.1  lukem    The DistinguishedName (1.3.6.1.4.1.1466.115.121.1.12) syntax and the
    665  1.1  lukem    'distinguishedNameMatch' rule are described in [RFC4517].
    666  1.1  lukem 
    667  1.1  lukem 2.24.  uniqueIdentifier
    668  1.1  lukem 
    669  1.1  lukem    The 'uniqueIdentifier' attribute specifies a unique identifier for an
    670  1.1  lukem    object represented in the Directory.  The domain within which the
    671  1.1  lukem    identifier is unique and the exact semantics of the identifier are
    672  1.1  lukem    for local definition.  For a person, this might be an institution-
    673  1.1  lukem    wide payroll number.  For an organizational unit, it might be a
    674  1.1  lukem    department code.
    675  1.1  lukem 
    676  1.1  lukem       ( 0.9.2342.19200300.100.1.44 NAME 'uniqueIdentifier'
    677  1.1  lukem         EQUALITY caseIgnoreMatch
    678  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    679  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    680  1.1  lukem 
    681  1.1  lukem 
    682  1.1  lukem 
    683  1.1  lukem 
    684  1.1  lukem 
    685  1.1  lukem Zeilenga                    Standards Track                    [Page 12]
    686  1.1  lukem 
    688  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    689  1.1  lukem 
    690  1.1  lukem 
    691  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    692  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    693  1.1  lukem    in [RFC4517].
    694  1.1  lukem 
    695  1.1  lukem    Note: X.520 also describes an attribute called 'uniqueIdentifier'
    696  1.1  lukem          (2.5.4.45), which is called 'x500UniqueIdentifier' in LDAP
    697  1.1  lukem          [RFC4519].  The attribute detailed here ought not be confused
    698  1.1  lukem          with 'x500UniqueIdentifier'.
    699  1.1  lukem 
    700  1.1  lukem 2.25.  userClass
    701  1.1  lukem 
    702  1.1  lukem    The 'userClass' attribute specifies categories of computer or
    703  1.1  lukem    application user.  The semantics placed on this attribute are for
    704  1.1  lukem    local interpretation.  Examples of current usage of this attribute in
    705  1.1  lukem    academia are "student", "staff", and "faculty".  Note that the
    706  1.1  lukem    'organizationalStatus' attribute type is now often preferred, as it
    707  1.1  lukem    makes no distinction between persons as opposed to users.
    708  1.1  lukem 
    709  1.1  lukem       ( 0.9.2342.19200300.100.1.8 NAME 'userClass'
    710  1.1  lukem         EQUALITY caseIgnoreMatch
    711  1.1  lukem         SUBSTR caseIgnoreSubstringsMatch
    712  1.1  lukem         SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
    713  1.1  lukem 
    714  1.1  lukem    The DirectoryString (1.3.6.1.4.1.1466.115.121.1.15) syntax and the
    715  1.1  lukem    'caseIgnoreMatch' and 'caseIgnoreSubstringsMatch' rules are described
    716  1.1  lukem    in [RFC4517].
    717  1.1  lukem 
    718  1.1  lukem 3.  COSINE Object Classes
    719  1.1  lukem 
    720  1.1  lukem    This section details COSINE object classes for use in LDAP.
    721  1.1  lukem 
    722  1.1  lukem 3.1.  account
    723  1.1  lukem 
    724  1.1  lukem    The 'account' object class is used to define entries representing
    725  1.1  lukem    computer accounts.  The 'uid' attribute SHOULD be used for naming
    726  1.1  lukem    entries of this object class.
    727  1.1  lukem 
    728  1.1  lukem       ( 0.9.2342.19200300.100.4.5 NAME 'account'
    729  1.1  lukem         SUP top STRUCTURAL
    730  1.1  lukem         MUST uid
    731  1.1  lukem         MAY ( description $ seeAlso $ l $ o $ ou $ host ) )
    732  1.1  lukem 
    733  1.1  lukem    The 'top' object class is described in [RFC4512].  The 'description',
    734  1.1  lukem    'seeAlso', 'l', 'o', 'ou', and 'uid' attribute types are described in
    735  1.1  lukem    [RFC4519].  The 'host' attribute type is described in Section 2 of
    736  1.1  lukem    this document.
    737  1.1  lukem 
    738  1.1  lukem 
    739  1.1  lukem 
    740  1.1  lukem 
    741  1.1  lukem 
    742  1.1  lukem Zeilenga                    Standards Track                    [Page 13]
    743  1.1  lukem 
    745  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    746  1.1  lukem 
    747  1.1  lukem 
    748  1.1  lukem    3.3.  documentSeriesExample:
    749  1.1  lukem 
    750  1.1  lukem       dn: uid=kdz,cn=Accounts,dc=Example,dc=COM
    751  1.1  lukem       objectClass: account
    752  1.1  lukem       uid: kdz
    753  1.1  lukem       seeAlso: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM
    754  1.1  lukem 
    755  1.1  lukem 3.2.  document
    756  1.1  lukem 
    757  1.1  lukem    The 'document' object class is used to define entries that represent
    758  1.1  lukem    documents.
    759  1.1  lukem 
    760  1.1  lukem       ( 0.9.2342.19200300.100.4.6 NAME 'document'
    761  1.1  lukem         SUP top STRUCTURAL
    762  1.1  lukem         MUST documentIdentifier
    763  1.1  lukem         MAY ( cn $ description $ seeAlso $ l $ o $ ou $
    764  1.1  lukem           documentTitle $ documentVersion $ documentAuthor $
    765  1.1  lukem           documentLocation $ documentPublisher ) )
    766  1.1  lukem 
    767  1.1  lukem    The 'top' object class is described in [RFC4512].  The 'cn',
    768  1.1  lukem    'description', 'seeAlso', 'l', 'o', and 'ou' attribute types are
    769  1.1  lukem    described in [RFC4519].  The 'documentIdentifier', 'documentTitle',
    770  1.1  lukem    'documentVersion', 'documentAuthor', 'documentLocation', and
    771  1.1  lukem    'documentPublisher' attribute types are described in Section 2 of
    772  1.1  lukem    this document.
    773  1.1  lukem 
    774  1.1  lukem    Example:
    775  1.1  lukem 
    776  1.1  lukem       dn: documentIdentifier=RFC 4524,cn=RFC,dc=Example,dc=COM
    777  1.1  lukem       objectClass: document
    778  1.1  lukem       documentIdentifier: RFC 4524
    779  1.1  lukem       documentTitle: COSINE LDAP/X.500 Schema
    780  1.1  lukem       documentAuthor: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM
    781  1.1  lukem       documentLocation: http://www.rfc-editor.org/rfc/rfc4524.txt
    782  1.1  lukem       documentPublisher: Internet Engineering Task Force
    783  1.1  lukem       description: A collection of schema elements for use in LDAP
    784  1.1  lukem       description: Obsoletes RFC 1274
    785  1.1  lukem       seeAlso: documentIdentifier=RFC 4510,cn=RFC,dc=Example,dc=COM
    786  1.1  lukem       seeAlso: documentIdentifier=RFC 1274,cn=RFC,dc=Example,dc=COM
    787  1.1  lukem 
    788  1.1  lukem 3.3.  documentSeries
    789  1.1  lukem 
    790  1.1  lukem    The 'documentSeries' object class is used to define an entry that
    791  1.1  lukem    represents a series of documents (e.g., The Request For Comments
    792  1.1  lukem    memos).
    793  1.1  lukem 
    794  1.1  lukem 
    795  1.1  lukem 
    796  1.1  lukem 
    797  1.1  lukem 
    798  1.1  lukem 
    799  1.1  lukem Zeilenga                    Standards Track                    [Page 14]
    800  1.1  lukem 
    802  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    803  1.1  lukem 
    804  1.1  lukem 
    805  1.1  lukem       ( 0.9.2342.19200300.100.4.9 NAME 'documentSeries'
    806  1.1  lukem         SUP top STRUCTURAL
    807  1.1  lukem         MUST cn
    808  1.1  lukem         MAY ( description $ l $ o $ ou $ seeAlso $
    809  1.1  lukem           telephonenumber ) )
    810  1.1  lukem 
    811  1.1  lukem    The 'top' object class is described in [RFC4512].  The 'description',
    812  1.1  lukem    'l', 'o', 'ou', 'seeAlso', and 'telephoneNumber' attribute types are
    813  1.1  lukem    described in [RFC4519].
    814  1.1  lukem 
    815  1.1  lukem    Example:
    816  1.1  lukem 
    817  1.1  lukem       dn: cn=RFC,dc=Example,dc=COM
    818  1.1  lukem       objectClass: documentSeries
    819  1.1  lukem       cn: Request for Comments
    820  1.1  lukem       cn: RFC
    821  1.1  lukem       description: a series of memos about the Internet
    822  1.1  lukem 
    823  1.1  lukem 3.4.  domain
    824  1.1  lukem 
    825  1.1  lukem    The 'domain' object class is used to define entries that represent
    826  1.1  lukem    DNS domains for objects that are not organizations, organizational
    827  1.1  lukem    units, or other kinds of objects more appropriately defined using an
    828  1.1  lukem    object class specific to the kind of object being defined (e.g.,
    829  1.1  lukem    'organization', 'organizationUnit').
    830  1.1  lukem 
    831  1.1  lukem    The 'dc' attribute should be used for naming entries of the 'domain'
    832  1.1  lukem    object class.
    833  1.1  lukem 
    834  1.1  lukem       ( 0.9.2342.19200300.100.4.13 NAME 'domain'
    835  1.1  lukem         SUP top STRUCTURAL
    836  1.1  lukem         MUST dc
    837  1.1  lukem         MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $
    838  1.1  lukem           x121Address $ registeredAddress $ destinationIndicator $
    839  1.1  lukem           preferredDeliveryMethod $ telexNumber $
    840  1.1  lukem           teletexTerminalIdentifier $ telephoneNumber $
    841  1.1  lukem           internationaliSDNNumber $ facsimileTelephoneNumber $ street $
    842  1.1  lukem           postOfficeBox $ postalCode $ postalAddress $
    843  1.1  lukem           physicalDeliveryOfficeName $ st $ l $ description $ o $
    844  1.1  lukem           associatedName ) )
    845  1.1  lukem 
    846  1.1  lukem    The 'top' object class and the 'dc', 'userPassword', 'searchGuide',
    847  1.1  lukem    'seeAlso', 'businessCategory', 'x121Address', 'registeredAddress',
    848  1.1  lukem    'destinationIndicator', 'preferredDeliveryMethod', 'telexNumber',
    849  1.1  lukem    'teletexTerminalIdentifier', 'telephoneNumber',
    850  1.1  lukem    'internationaliSDNNumber', 'facsimileTelephoneNumber', 'street',
    851  1.1  lukem    'postOfficeBox', 'postalCode', 'postalAddress',
    852  1.1  lukem    'physicalDeliveryOfficeName', 'st', 'l', 'description', and 'o' types
    853  1.1  lukem 
    854  1.1  lukem 
    855  1.1  lukem 
    856  1.1  lukem Zeilenga                    Standards Track                    [Page 15]
    857  1.1  lukem 
    859  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    860  1.1  lukem 
    861  1.1  lukem 
    862  1.1  lukem    are described in [RFC4519].  The 'associatedName' attribute type is
    863  1.1  lukem    described in Section 2 of this document.
    864  1.1  lukem 
    865  1.1  lukem    Example:
    866  1.1  lukem 
    867  1.1  lukem       dn: dc=com
    868  1.1  lukem       objectClass: domain
    869  1.1  lukem       dc: com
    870  1.1  lukem       description: the .COM TLD
    871  1.1  lukem 
    872  1.1  lukem 3.5.  domainRelatedObject
    873  1.1  lukem 
    874  1.1  lukem    The 'domainRelatedObject' object class is used to define entries that
    875  1.1  lukem    represent DNS domains that are "equivalent" to an X.500 domain, e.g.,
    876  1.1  lukem    an organization or organizational unit.
    877  1.1  lukem 
    878  1.1  lukem       ( 0.9.2342.19200300.100.4.17 NAME 'domainRelatedObject'
    879  1.1  lukem         SUP top AUXILIARY
    880  1.1  lukem         MUST associatedDomain )
    881  1.1  lukem 
    882  1.1  lukem    The 'top' object class is described in [RFC4512].  The
    883  1.1  lukem    'associatedDomain' attribute type is described in Section 2 of this
    884  1.1  lukem    document.
    885  1.1  lukem 
    886  1.1  lukem    Example:
    887  1.1  lukem 
    888  1.1  lukem       dn: dc=example,dc=com
    889  1.1  lukem       objectClass: organization
    890  1.1  lukem       objectClass: dcObject
    891  1.1  lukem       objectClass: domainRelatedObject
    892  1.1  lukem       dc: example
    893  1.1  lukem       associatedDomain: example.com
    894  1.1  lukem       o: Example Organization
    895  1.1  lukem 
    896  1.1  lukem    The 'organization' and 'dcObject' object classes and the 'dc' and 'o'
    897  1.1  lukem    attribute types are described in [RFC4519].
    898  1.1  lukem 
    899  1.1  lukem 3.6.  friendlyCountry
    900  1.1  lukem 
    901  1.1  lukem    The 'friendlyCountry' object class is used to define entries
    902  1.1  lukem    representing countries in the DIT.  The object class is used to allow
    903  1.1  lukem    friendlier naming of countries than that allowed by the object class
    904  1.1  lukem    'country' [RFC4519].
    905  1.1  lukem 
    906  1.1  lukem       ( 0.9.2342.19200300.100.4.18 NAME 'friendlyCountry'
    907  1.1  lukem         SUP country STRUCTURAL
    908  1.1  lukem         MUST co )
    909  1.1  lukem 
    910  1.1  lukem 
    911  1.1  lukem 
    912  1.1  lukem 
    913  1.1  lukem Zeilenga                    Standards Track                    [Page 16]
    914  1.1  lukem 
    916  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    917  1.1  lukem 
    918  1.1  lukem 
    919  1.1  lukem    The 'country' object class is described in [RFC4519].  The 'co'
    920  1.1  lukem    attribute type is described in Section 2 of this document.
    921  1.1  lukem 
    922  1.1  lukem    Example:
    923  1.1  lukem 
    924  1.1  lukem       dn: c=DE
    925  1.1  lukem       objectClass: country
    926  1.1  lukem       objectClass: friendlyCountry
    927  1.1  lukem       c: DE
    928  1.1  lukem       co: Deutschland
    929  1.1  lukem       co: Germany
    930  1.1  lukem       co: Federal Republic of Germany
    931  1.1  lukem       co: FRG
    932  1.1  lukem 
    933  1.1  lukem    The 'c' attribute type is described in [RFC4519].
    934  1.1  lukem 
    935  1.1  lukem 3.7.  rFC822LocalPart
    936  1.1  lukem 
    937  1.1  lukem    The 'rFC822LocalPart' object class is used to define entries that
    938  1.1  lukem    represent the local part of Internet mail addresses [RFC2822].  This
    939  1.1  lukem    treats the local part of the address as a 'domain' object.
    940  1.1  lukem 
    941  1.1  lukem       ( 0.9.2342.19200300.100.4.14 NAME 'rFC822localPart'
    942  1.1  lukem         SUP domain STRUCTURAL
    943  1.1  lukem         MAY ( cn $ description $ destinationIndicator $
    944  1.1  lukem           facsimileTelephoneNumber $ internationaliSDNNumber $
    945  1.1  lukem           physicalDeliveryOfficeName $ postalAddress $ postalCode $
    946  1.1  lukem           postOfficeBox $ preferredDeliveryMethod $ registeredAddress $
    947  1.1  lukem           seeAlso $ sn $ street $ telephoneNumber $
    948  1.1  lukem           teletexTerminalIdentifier $ telexNumber $ x121Address ) )
    949  1.1  lukem 
    950  1.1  lukem    The 'domain' object class is described in Section 3.4 of this
    951  1.1  lukem    document.  The 'cn', 'description', 'destinationIndicator',
    952  1.1  lukem    'facsimileTelephoneNumber', 'internationaliSDNNumber,
    953  1.1  lukem    'physicalDeliveryOfficeName', 'postalAddress', 'postalCode',
    954  1.1  lukem    'postOfficeBox', 'preferredDeliveryMethod', 'registeredAddress',
    955  1.1  lukem    'seeAlso', 'sn, 'street', 'telephoneNumber',
    956  1.1  lukem    'teletexTerminalIdentifier', 'telexNumber', and 'x121Address'
    957  1.1  lukem    attribute types are described in [RFC4519].
    958  1.1  lukem 
    959  1.1  lukem    Example:
    960  1.1  lukem 
    961  1.1  lukem       dn: dc=kdz,dc=example,dc=com
    962  1.1  lukem       objectClass: domain
    963  1.1  lukem       objectClass: rFC822LocalPart
    964  1.1  lukem       dc: kdz
    965  1.1  lukem       associatedName: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM
    966  1.1  lukem 
    967  1.1  lukem 
    968  1.1  lukem 
    969  1.1  lukem 
    970  1.1  lukem Zeilenga                    Standards Track                    [Page 17]
    971  1.1  lukem 
    973  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
    974  1.1  lukem 
    975  1.1  lukem 
    976  1.1  lukem    The 'dc' attribute type is described in [RFC4519].
    977  1.1  lukem 
    978  1.1  lukem 3.8.  room
    979  1.1  lukem 
    980  1.1  lukem    The 'room' object class is used to define entries representing rooms.
    981  1.1  lukem    The 'cn' (commonName) attribute SHOULD be used for naming entries of
    982  1.1  lukem    this object class.
    983  1.1  lukem 
    984  1.1  lukem       ( 0.9.2342.19200300.100.4.7 NAME 'room'
    985  1.1  lukem         SUP top STRUCTURAL
    986  1.1  lukem         MUST cn
    987  1.1  lukem         MAY ( roomNumber $ description $ seeAlso $ telephoneNumber ) )
    988  1.1  lukem 
    989  1.1  lukem    The 'top' object class is described in [RFC4512].  The 'cn',
    990  1.1  lukem    'description', 'seeAlso', and 'telephoneNumber' attribute types are
    991  1.1  lukem    described in [RFC4519].  The 'roomNumber' attribute type is described
    992  1.1  lukem    in Section 2 of this document.
    993  1.1  lukem 
    994  1.1  lukem       dn: cn=conference room,dc=example,dc=com
    995  1.1  lukem       objectClass: room
    996  1.1  lukem       cn: conference room
    997  1.1  lukem       telephoneNumber: +1 755 555 1111
    998  1.1  lukem 
    999  1.1  lukem 3.9.  simpleSecurityObject
   1000  1.1  lukem 
   1001  1.1  lukem    The 'simpleSecurityObject' object class is used to require an entry
   1002  1.1  lukem    to have a 'userPassword' attribute when the entry's structural object
   1003  1.1  lukem    class does not require (or allow) the 'userPassword attribute'.
   1004  1.1  lukem 
   1005  1.1  lukem       ( 0.9.2342.19200300.100.4.19 NAME 'simpleSecurityObject'
   1006  1.1  lukem         SUP top AUXILIARY
   1007  1.1  lukem         MUST userPassword )
   1008  1.1  lukem 
   1009  1.1  lukem    The 'top' object class is described in [RFC4512].  The 'userPassword'
   1010  1.1  lukem    attribute type is described in [RFC4519].
   1011  1.1  lukem 
   1012  1.1  lukem       dn: dc=kdz,dc=Example,dc=COM
   1013  1.1  lukem       objectClass: account
   1014  1.1  lukem       objectClass: simpleSecurityObject
   1015  1.1  lukem       uid: kdz
   1016  1.1  lukem       userPassword: My Password
   1017  1.1  lukem       seeAlso: cn=Kurt D. Zeilenga,cn=Persons,dc=Example,dc=COM
   1018  1.1  lukem 
   1019  1.1  lukem 4.  Security Considerations
   1020  1.1  lukem 
   1021  1.1  lukem    General LDAP security considerations [RFC4510] are applicable to the
   1022  1.1  lukem    use of this schema.  Additional considerations are noted above where
   1023  1.1  lukem    appropriate.
   1024  1.1  lukem 
   1025  1.1  lukem 
   1026  1.1  lukem 
   1027  1.1  lukem Zeilenga                    Standards Track                    [Page 18]
   1028  1.1  lukem 
   1030  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1031  1.1  lukem 
   1032  1.1  lukem 
   1033  1.1  lukem    Directories administrators should ensure that access to sensitive
   1034  1.1  lukem    information be restricted to authorized entities and that appropriate
   1035  1.1  lukem    data security services, including data integrity and data
   1036  1.1  lukem    confidentiality, are used to protect against eavesdropping.
   1037  1.1  lukem 
   1038  1.1  lukem    Simple authentication (e.g., plain text passwords) mechanisms should
   1039  1.1  lukem    only be used when adequate data security services are in place.  LDAP
   1040  1.1  lukem    offers reasonably strong authentication and data security services
   1041  1.1  lukem    [RFC4513].
   1042  1.1  lukem 
   1043  1.1  lukem 5.  IANA Considerations
   1044  1.1  lukem 
   1045  1.1  lukem    The Internet Assigned Numbers Authority (IANA) has updated the LDAP
   1046  1.1  lukem    descriptors registry [RFC4520] as indicated in the following
   1047  1.1  lukem    template:
   1048  1.1  lukem 
   1049  1.1  lukem       Subject: Request for LDAP Descriptor Registration Update
   1050  1.1  lukem       Descriptor (short name): see comment
   1051  1.1  lukem       Object Identifier: see comments
   1052  1.1  lukem       Person & email address to contact for further information:
   1053  1.1  lukem           Kurt Zeilenga <kurt (a] OpenLDAP.org>
   1054  1.1  lukem       Usage: see comments
   1055  1.1  lukem       Specification: RFC 4524
   1056  1.1  lukem       Author/Change Controller: IESG
   1057  1.1  lukem       Comments:
   1058  1.1  lukem 
   1059  1.1  lukem       The following descriptors have been updated to refer to RFC 4524.
   1060  1.1  lukem 
   1061  1.1  lukem         NAME                           Type OID
   1062  1.1  lukem         ------------------------       ---- --------------------------
   1063  1.1  lukem         account                        O    0.9.2342.19200300.100.4.5
   1064  1.1  lukem         associatedDomain               A    0.9.2342.19200300.100.1.37
   1065  1.1  lukem         associatedName                 A    0.9.2342.19200300.100.1.38
   1066  1.1  lukem         buildingName                   A    0.9.2342.19200300.100.1.48
   1067  1.1  lukem         co                             A    0.9.2342.19200300.100.1.43
   1068  1.1  lukem         document                       O    0.9.2342.19200300.100.4.6
   1069  1.1  lukem         documentAuthor                 A    0.9.2342.19200300.100.1.14
   1070  1.1  lukem         documentIdentifier             A    0.9.2342.19200300.100.1.11
   1071  1.1  lukem         documentLocation               A    0.9.2342.19200300.100.1.15
   1072  1.1  lukem         documentPublisher              A    0.9.2342.19200300.100.1.56
   1073  1.1  lukem         documentSeries                 O    0.9.2342.19200300.100.4.8
   1074  1.1  lukem         documentTitle                  A    0.9.2342.19200300.100.1.12
   1075  1.1  lukem         documentVersion                A    0.9.2342.19200300.100.1.13
   1076  1.1  lukem         domain                         O    0.9.2342.19200300.100.4.13
   1077  1.1  lukem         domainRelatedObject            O    0.9.2342.19200300.100.4.17
   1078  1.1  lukem         drink                          A    0.9.2342.19200300.100.1.5
   1079  1.1  lukem         favouriteDrink                 A*   0.9.2342.19200300.100.1.5
   1080  1.1  lukem         friendlyCountry                O    0.9.2342.19200300.100.4.18
   1081  1.1  lukem 
   1082  1.1  lukem 
   1083  1.1  lukem 
   1084  1.1  lukem Zeilenga                    Standards Track                    [Page 19]
   1085  1.1  lukem 
   1087  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1088  1.1  lukem 
   1089  1.1  lukem 
   1090  1.1  lukem         friendlyCountryName            A*   0.9.2342.19200300.100.1.43
   1091  1.1  lukem         homePhone                      A    0.9.2342.19200300.100.1.20
   1092  1.1  lukem         homePostalAddress              A    0.9.2342.19200300.100.1.39
   1093  1.1  lukem         homeTelephone                  A*   0.9.2342.19200300.100.1.20
   1094  1.1  lukem         host                           A    0.9.2342.19200300.100.1.9
   1095  1.1  lukem         info                           A    0.9.2342.19200300.100.1.4
   1096  1.1  lukem         mail                           A    0.9.2342.19200300.100.1.3
   1097  1.1  lukem         manager                        A    0.9.2342.19200300.100.1.10
   1098  1.1  lukem         mobile                         A    0.9.2342.19200300.100.1.41
   1099  1.1  lukem         mobileTelephoneNumber          A*   0.9.2342.19200300.100.1.41
   1100  1.1  lukem         organizationalStatus           A    0.9.2342.19200300.100.1.45
   1101  1.1  lukem         pager                          A    0.9.2342.19200300.100.1.42
   1102  1.1  lukem         pagerTelephoneNumber           A*   0.9.2342.19200300.100.1.42
   1103  1.1  lukem         personalTitle                  A    0.9.2342.19200300.100.1.40
   1104  1.1  lukem         rFC822LocalPart                O    0.9.2342.19200300.100.4.14
   1105  1.1  lukem         rfc822Mailbox                  A*   0.9.2342.19200300.100.1.3
   1106  1.1  lukem         room                           O    0.9.2342.19200300.100.4.7
   1107  1.1  lukem         roomNumber                     A    0.9.2342.19200300.100.1.6
   1108  1.1  lukem         secretary                      A    0.9.2342.19200300.100.1.21
   1109  1.1  lukem         simpleSecurityObject           O    0.9.2342.19200300.100.4.19
   1110  1.1  lukem         singleLevelQuality             A    0.9.2342.19200300.100.1.50
   1111  1.1  lukem         uniqueIdentifier               A    0.9.2342.19200300.100.1.44
   1112  1.1  lukem         userClass                      A    0.9.2342.19200300.100.1.8
   1113  1.1  lukem 
   1114  1.1  lukem       where Type A is Attribute, Type O is ObjectClass, and *
   1115  1.1  lukem       indicates that the registration is historic in nature.
   1116  1.1  lukem 
   1117  1.1  lukem 6.  Acknowledgements
   1118  1.1  lukem 
   1119  1.1  lukem    This document is based on RFC 1274, by Paul Barker and Steve Kille,
   1120  1.1  lukem    as well as on RFC 2247, by Steve Kill, Mark Wahl, Al Grimstad, Rick
   1121  1.1  lukem    Huber, and Sri Satulari.
   1122  1.1  lukem 
   1123  1.1  lukem 7.  References
   1124  1.1  lukem 
   1125  1.1  lukem 7.1.  Normative References
   1126  1.1  lukem 
   1127  1.1  lukem    [RFC1034]     Mockapetris, P., "Domain names - concepts and
   1128  1.1  lukem                  facilities", STD 13, RFC 1034, November 1987.
   1129  1.1  lukem 
   1130  1.1  lukem    [RFC1123]     Braden, R., "Requirements for Internet Hosts -
   1131  1.1  lukem                  Application and Support", STD 3, RFC 1123, October
   1132  1.1  lukem                  1989.
   1133  1.1  lukem 
   1134  1.1  lukem    [RFC2119]     Bradner, S., "Key words for use in RFCs to Indicate
   1135  1.1  lukem                  Requirement Levels", BCP 14, RFC 2119, March 1997.
   1136  1.1  lukem 
   1137  1.1  lukem 
   1138  1.1  lukem 
   1139  1.1  lukem 
   1140  1.1  lukem 
   1141  1.1  lukem Zeilenga                    Standards Track                    [Page 20]
   1142  1.1  lukem 
   1144  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1145  1.1  lukem 
   1146  1.1  lukem 
   1147  1.1  lukem    [RFC2181]     Elz, R. and R. Bush, "Clarifications to the DNS
   1148  1.1  lukem                  Specification", RFC 2181, July 1997.
   1149  1.1  lukem 
   1150  1.1  lukem    [RFC2247]     Kille, S., Wahl, M., Grimstad, A., Huber, R., and S.
   1151  1.1  lukem                  Sataluri, "Using Domains in LDAP/X.500 Distinguished
   1152  1.1  lukem                  Names", RFC 2247, January 1998.
   1153  1.1  lukem 
   1154  1.1  lukem    [RFC2821]     Klensin, J., Ed., "Simple Mail Transfer Protocol", RFC
   1155  1.1  lukem                  2821, April 2001.
   1156  1.1  lukem 
   1157  1.1  lukem    [RFC2822]     Resnick, P., "Internet Message Format", RFC 2822, April
   1158  1.1  lukem                  2001.
   1159  1.1  lukem 
   1160  1.1  lukem    [RFC3490]     Faltstrom, P., Hoffman, P., and A. Costello,
   1161  1.1  lukem                  "Internationalizing Domain Names in Applications
   1162  1.1  lukem                  (IDNA)", RFC 3490, March 2003.
   1163  1.1  lukem 
   1164  1.1  lukem    [RFC4510]     Zeilenga, K., Ed.,  "Lightweight Directory Access
   1165  1.1  lukem                  Protocol (LDAP): Technical Specification Road Map", RFC
   1166  1.1  lukem                  4510, June 2006.
   1167  1.1  lukem 
   1168  1.1  lukem    [RFC4512]     Zeilenga, K., "Lightweight Directory Access Protocol
   1169  1.1  lukem                  (LDAP): Directory Information Models", RFC 4512, June
   1170  1.1  lukem                  2006.
   1171  1.1  lukem 
   1172  1.1  lukem    [RFC4513]     Harrison, R., "Lightweight Directory Access Protocol
   1173  1.1  lukem                  (LDAP): Authentication Methods and Security
   1174  1.1  lukem                  Mechanisms", RFC 4513, June 2006.
   1175  1.1  lukem 
   1176  1.1  lukem    [RFC4517]     Legg, S., Ed., "Lightweight Directory Access Protocol
   1177  1.1  lukem                  (LDAP): Syntaxes and Matching Rules", RC 4517, June
   1178  1.1  lukem                  2006.
   1179  1.1  lukem 
   1180  1.1  lukem    [RFC4519]     Sciberras, A., Ed., "Lightweight Directory Access
   1181  1.1  lukem                  Protocol (LDAP): Schema for User Applications", RFC
   1182  1.1  lukem                  4519, June 2006.
   1183  1.1  lukem 
   1184  1.1  lukem    [X.501]       International Telecommunication Union -
   1185  1.1  lukem                  Telecommunication Standardization Sector, "The
   1186  1.1  lukem                  Directory -- Models," X.501(1993) (also ISO/IEC 9594-
   1187  1.1  lukem                  2:1994).
   1188  1.1  lukem 
   1189  1.1  lukem 7.2.  Informative References
   1190  1.1  lukem 
   1191  1.1  lukem    [COSINEpilot] Goodman, D., "PARADISE" section of the March 1991
   1192  1.1  lukem                  INTERNET MONTHLY REPORTS (p. 28-29),
   1193  1.1  lukem                  http://www.iana.org/periodic-reports/imr-mar91.txt
   1194  1.1  lukem 
   1195  1.1  lukem 
   1196  1.1  lukem 
   1197  1.1  lukem 
   1198  1.1  lukem Zeilenga                    Standards Track                    [Page 21]
   1199  1.1  lukem 
   1201  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1202  1.1  lukem 
   1203  1.1  lukem 
   1204  1.1  lukem    [ISO3166]     International Organization for Standardization, "Codes
   1205  1.1  lukem                  for the representation of names of countries", ISO
   1206  1.1  lukem                  3166.
   1207  1.1  lukem 
   1208  1.1  lukem    [RFC1274]     Barker, P. and S. Kille, "The COSINE and Internet X.500
   1209  1.1  lukem                  Schema", RFC 1274, November 1991.
   1210  1.1  lukem 
   1211  1.1  lukem    [RFC1279]     Hardcastle-Kille, S., "X.500 and Domains", RFC 1279,
   1212  1.1  lukem                  November 1991.
   1213  1.1  lukem 
   1214  1.1  lukem    [RFC1487]     Yeong, W., Howes, T., and S. Kille, "X.500 Lightweight
   1215  1.1  lukem                  Directory Access Protocol", RFC 1487, July 1993.
   1216  1.1  lukem 
   1217  1.1  lukem    [RFC2251]     Wahl, M., Howes, T., and S. Kille, "Lightweight
   1218  1.1  lukem                  Directory Access Protocol (v3)", RFC 2251, December
   1219  1.1  lukem                  1997.
   1220  1.1  lukem 
   1221  1.1  lukem    [RFC2798]     Smith, M., "Definition of the inetOrgPerson LDAP Object
   1222  1.1  lukem                  Class", RFC 2798, April 2000.
   1223  1.1  lukem 
   1224  1.1  lukem    [RFC3494]     Zeilenga, K., "Lightweight Directory Access Protocol
   1225  1.1  lukem                  version 2 (LDAPv2) to Historic Status", RFC 3494, March
   1226  1.1  lukem                  2003.
   1227  1.1  lukem 
   1228  1.1  lukem    [RFC4520]     Zeilenga, K., "Internet Assigned Numbers Authority
   1229  1.1  lukem                  (IANA) Considerations for the Lightweight Directory
   1230  1.1  lukem                  Access Protocol (LDAP)", BCP 64, RFC 4520.
   1231  1.1  lukem 
   1232  1.1  lukem 
   1233  1.1  lukem 
   1234  1.1  lukem 
   1235  1.1  lukem 
   1236  1.1  lukem 
   1237  1.1  lukem 
   1238  1.1  lukem 
   1239  1.1  lukem 
   1240  1.1  lukem 
   1241  1.1  lukem 
   1242  1.1  lukem 
   1243  1.1  lukem 
   1244  1.1  lukem 
   1245  1.1  lukem 
   1246  1.1  lukem 
   1247  1.1  lukem 
   1248  1.1  lukem 
   1249  1.1  lukem 
   1250  1.1  lukem 
   1251  1.1  lukem 
   1252  1.1  lukem 
   1253  1.1  lukem 
   1254  1.1  lukem 
   1255  1.1  lukem Zeilenga                    Standards Track                    [Page 22]
   1256  1.1  lukem 
   1258  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1259  1.1  lukem 
   1260  1.1  lukem 
   1261  1.1  lukem Appendix A.  Changes since RFC 1274
   1262  1.1  lukem 
   1263  1.1  lukem    This document represents a substantial rewrite of RFC 1274.  The
   1264  1.1  lukem    following sections summarize the substantive changes.
   1265  1.1  lukem 
   1266  1.1  lukem A.1.  LDAP Short Names
   1267  1.1  lukem 
   1268  1.1  lukem    A number of COSINE attribute types have short names in LDAP.
   1269  1.1  lukem 
   1270  1.1  lukem       X.500 Name              LDAP Short Name
   1271  1.1  lukem       -------------           ---------------
   1272  1.1  lukem       domainComponent         dc
   1273  1.1  lukem       favoriteDrink           drink
   1274  1.1  lukem       friendCountryName       co
   1275  1.1  lukem       homeTelephoneNumber     homePhone
   1276  1.1  lukem       mobileTelephoneNumber   mobile
   1277  1.1  lukem       pagerTelephoneNumber    pager
   1278  1.1  lukem       rfc822Mailbox           mail
   1279  1.1  lukem       userid                  uid
   1280  1.1  lukem 
   1281  1.1  lukem    While the LDAP short names are generally used in LDAP, some
   1282  1.1  lukem    implementations may (for legacy reasons [RFC3494]) recognize the
   1283  1.1  lukem    attribute type by its X.500 name.  Hence, the X.500 names have been
   1284  1.1  lukem    reserved solely for this purpose.
   1285  1.1  lukem 
   1286  1.1  lukem    Note: 'uid' and 'dc' are described in [RFC4519].
   1287  1.1  lukem 
   1288  1.1  lukem A.2.  pilotObject
   1289  1.1  lukem 
   1290  1.1  lukem    The 'pilotObject' object class was not brought forward as its
   1291  1.1  lukem    function is largely replaced by operational attributes introduced in
   1292  1.1  lukem    X.500(93) [X.501] and version 3 of LDAP [RFC4512].  For instance, the
   1293  1.1  lukem    function of the 'lastModifiedBy' and 'lastModifiedTime' attribute
   1294  1.1  lukem    types is now served by the 'creatorsName', 'createTimestamp',
   1295  1.1  lukem    'modifiersName', and 'modifyTimestamp' operational attributes
   1296  1.1  lukem    [RFC4512].
   1297  1.1  lukem 
   1298  1.1  lukem A.3.  pilotPerson
   1299  1.1  lukem 
   1300  1.1  lukem    The 'pilotPerson' object class was not brought forward as its
   1301  1.1  lukem    function is largely replaced by the 'organizationalPerson' [RFC4512]
   1302  1.1  lukem    object class and its subclasses, such as 'inetOrgPerson' [RFC2798].
   1303  1.1  lukem 
   1304  1.1  lukem    Most of the related attribute types (e.g., 'mail', 'manager') were
   1305  1.1  lukem    brought forward as they are used in other object classes.
   1306  1.1  lukem 
   1307  1.1  lukem 
   1308  1.1  lukem 
   1309  1.1  lukem 
   1310  1.1  lukem 
   1311  1.1  lukem 
   1312  1.1  lukem Zeilenga                    Standards Track                    [Page 23]
   1313  1.1  lukem 
   1315  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1316  1.1  lukem 
   1317  1.1  lukem 
   1318  1.1  lukem A.4.  dNSDomain
   1319  1.1  lukem 
   1320  1.1  lukem    The 'dNSDomain' object class and related attribute types were not
   1321  1.1  lukem    brought forward as its use is primarily experimental [RFC1279].
   1322  1.1  lukem 
   1323  1.1  lukem A.5.  pilotDSA and qualityLabelledData
   1324  1.1  lukem 
   1325  1.1  lukem    The 'pilotDSA' and 'qualityLabelledData' object classes, as well as
   1326  1.1  lukem    related attribute types, were not brought forward as its use is
   1327  1.1  lukem    primarily experimental [QoS].
   1328  1.1  lukem 
   1329  1.1  lukem A.6.  Attribute Syntaxes
   1330  1.1  lukem 
   1331  1.1  lukem    RFC 1274 defined and used caseIgnoreIA5StringSyntax attribute syntax.
   1332  1.1  lukem    This has been replaced with the IA5String syntax and appropriate
   1333  1.1  lukem    matching rules in 'mail' and 'associatedDomain'.
   1334  1.1  lukem 
   1335  1.1  lukem    RFC 1274 restricted 'mail' to have non-zero length values.  This
   1336  1.1  lukem    restriction is not reflected in the IA5String syntax used in the
   1337  1.1  lukem    definitions provided in this specification.  However, as values are
   1338  1.1  lukem    to conform to the <Mailbox> production, the 'mail' should not contain
   1339  1.1  lukem    zero-length values.  Unfortunately, the directory service will not
   1340  1.1  lukem    enforce this restriction.
   1341  1.1  lukem 
   1342  1.1  lukem Appendix B.  Changes since RFC 2247
   1343  1.1  lukem 
   1344  1.1  lukem    The 'domainNameForm' name form was not brought forward as
   1345  1.1  lukem    specification of name forms used in LDAP is left to a future
   1346  1.1  lukem    specification.
   1347  1.1  lukem 
   1348  1.1  lukem Editor's Address
   1349  1.1  lukem 
   1350  1.1  lukem    Kurt D. Zeilenga
   1351  1.1  lukem    OpenLDAP Foundation
   1352  1.1  lukem 
   1353  1.1  lukem    EMail: Kurt (a] OpenLDAP.org
   1354  1.1  lukem 
   1355  1.1  lukem 
   1356  1.1  lukem 
   1357  1.1  lukem 
   1358  1.1  lukem 
   1359  1.1  lukem 
   1360  1.1  lukem 
   1361  1.1  lukem 
   1362  1.1  lukem 
   1363  1.1  lukem 
   1364  1.1  lukem 
   1365  1.1  lukem 
   1366  1.1  lukem 
   1367  1.1  lukem 
   1368  1.1  lukem 
   1369  1.1  lukem Zeilenga                    Standards Track                    [Page 24]
   1370  1.1  lukem 
   1372  1.1  lukem RFC 4524                COSINE LDAP/X.500 Schema               June 2006
   1373  1.1  lukem 
   1374  1.1  lukem 
   1375  1.1  lukem Full Copyright Statement
   1376  1.1  lukem 
   1377  1.1  lukem    Copyright (C) The Internet Society (2006).
   1378  1.1  lukem 
   1379  1.1  lukem    This document is subject to the rights, licenses and restrictions
   1380  1.1  lukem    contained in BCP 78, and except as set forth therein, the authors
   1381  1.1  lukem    retain all their rights.
   1382  1.1  lukem 
   1383  1.1  lukem    This document and the information contained herein are provided on an
   1384  1.1  lukem    "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
   1385  1.1  lukem    OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET
   1386  1.1  lukem    ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED,
   1387  1.1  lukem    INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
   1388  1.1  lukem    INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
   1389  1.1  lukem    WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
   1390  1.1  lukem 
   1391  1.1  lukem Intellectual Property
   1392  1.1  lukem 
   1393  1.1  lukem    The IETF takes no position regarding the validity or scope of any
   1394  1.1  lukem    Intellectual Property Rights or other rights that might be claimed to
   1395  1.1  lukem    pertain to the implementation or use of the technology described in
   1396  1.1  lukem    this document or the extent to which any license under such rights
   1397  1.1  lukem    might or might not be available; nor does it represent that it has
   1398  1.1  lukem    made any independent effort to identify any such rights.  Information
   1399  1.1  lukem    on the procedures with respect to rights in RFC documents can be
   1400  1.1  lukem    found in BCP 78 and BCP 79.
   1401  1.1  lukem 
   1402  1.1  lukem    Copies of IPR disclosures made to the IETF Secretariat and any
   1403  1.1  lukem    assurances of licenses to be made available, or the result of an
   1404                attempt made to obtain a general license or permission for the use of
   1405                such proprietary rights by implementers or users of this
   1406                specification can be obtained from the IETF on-line IPR repository at
   1407                http://www.ietf.org/ipr.
   1408             
   1409                The IETF invites any interested party to bring to its attention any
   1410                copyrights, patents or patent applications, or other proprietary
   1411                rights that may cover technology that may be required to implement
   1412                this standard.  Please address the information to the IETF at
   1413                ietf-ipr (a] ietf.org.
   1414             
   1415             Acknowledgement
   1416             
   1417                Funding for the RFC Editor function is provided by the IETF
   1418                Administrative Support Activity (IASA).
   1419             
   1420             
   1421             
   1422             
   1423             
   1424             
   1425             
   1426             Zeilenga                    Standards Track                    [Page 25]
   1427             
   1429