ietf-corpus

rfc-1274

The COSINE and Internet X.500 Schema

P. Barker, S. Kille
date1991-11 streamIETF areaapp wgosids statusPROPOSED STANDARD pages60 canonicalhttps://www.rfc-editor.org/rfc/rfc1274 doi10.17487/RFC1274
This document suggests an X.500 Directory Schema, or Naming Architecture, for use in the COSINE and Internet X.500 pilots. [STANDARDS-TRACK]

obsoleted by

Extracted elements (29)

design-rationale §6

Old object classes and attribute types are retired gracefully: retirement intent is announced to the mailing list, the definition is marked with an expiry date and retained until that date, and users retain the right to argue for retention if no adequate replacement exists.

ldap, process

design-rationale §2

Private definitions of common object classes and attribute types across many directory administrators would diminish the directory's generality because remote systems would be unable to determine the semantics of privately-defined data types; a shared pilot schema avoids this fragmentation.

ldap

design-rationale §5

The pilotGroups OID subtree ({pilot 10}) is reserved for allocation of OID subtrees to groups of new experimental definitions, enabling flexibility during experimentation while keeping object identifiers coherent and avoiding disruptive reassignments once definitions are deployed at multiple sites.

ldap, registry

design-rationale §2

The schema is treated as a 'living document' requiring formal update procedures (proforma submissions, mailing-list review at na-update@cs.ucl.ac.uk) because experience with the THORN/RARE Naming Architecture showed that piloting requirements grow rapidly beyond any static definition.

ldap, process

design-rationale §9.3.2

The textEncodedORAddress attribute (pilotAttributeType 2) is explicitly deprecated and identified as the first candidate for the attribute expiry mechanism because it was intended only as an interim encoding of X.400 O/R addresses per RFC 987.

ldap, email

interoperability-note §4

Requests to modify an existing object class by changing its mandatory attribute types are refused; a new object class is created instead and the original is scheduled for expiry. Only additions of optional attributes are accommodated in-place, and implementations are expected to be resilient to such additive changes.

ldap

interoperability-note §9.3.3

The rfc822Mailbox attribute must not be used for greybook or other non-Internet-order mailboxes; those cases should use the otherMailbox attribute type instead.

ldap, email

normative-requirement §3 MUST

A DSA conforming to this schema shall be able to store all of the attributes and object class values specified, including all object classes and attribute types required by strong authentication as defined in X.509.

ldap, security

normative-requirement §3 MUST

A DUA conforming to this schema shall be able to identify each attribute type and object class to the user with an appropriate representation such as a string.

ldap

normative-requirement §9.3.36 MUST

Entries using the janetMailbox attribute MUST also include an rfc822Mailbox attribute, since janetMailbox uses Grey Book syntax intended only for UK users unfamiliar with RFC 822 addressing.

email, ldap

normative-requirement §3 MUST

For large attribute values greater than 1 kilobyte, a conforming DSA is not required to store them and a DUA is not required to display them, but the DUA must indicate their presence.

ldap

protocol-element §8.3.3

The account object class (pilotObjectClass 5) represents computer accounts with userid as the mandatory naming attribute, and optional attributes description, seeAlso, localityName, organizationName, organizationalUnitName, and host.

ldap

protocol-element §9.3.44

The dITRedirect attribute (pilotAttributeType 54) contains a distinguishedName pointing to the newer DIT entry for an object that has moved (e.g., changed employer); the redirecting entry should be expired after a suitable grace period.

ldap

protocol-element §8.3.9

The dNSDomain object class (pilotObjectClass 15) extends domain with optional DNS resource record attributes: ARecord, MDRecord, MXRecord, NSRecord, SOARecord, and CNAMERecord.

ldap, dns

protocol-element §8.3.7

The domain object class (pilotObjectClass 13) represents DNS or NRS domains; domainComponent is the mandatory naming attribute, and entries may include associatedName and organizationalAttributeSet.

ldap, dns

protocol-element §9.3.21

The domainComponent attribute (pilotAttributeType 25) is a SINGLE VALUE caseIgnoreIA5String specifying one DNS or NRS domain label (e.g., 'uk' or 'ac'); it serves as the naming attribute for domain entries.

ldap, dns

protocol-element §8.3.10

The domainRelatedObject object class (pilotObjectClass 17) links X.500 DIT entries to equivalent DNS or NRS domains by requiring associatedDomain as a mandatory attribute.

ldap, dns

protocol-element §8.3.11

The friendlyCountry object class (pilotObjectClass 18) extends the standard country class to permit human-readable country names via the mandatory friendlyCountryName attribute, since the standard countryName is restricted to 2-letter ISO 3166 codes.

ldap

protocol-element §9.3.37

The mailPreferenceOption attribute (pilotAttributeType 47) is an ENUMERATED type with values no-list-inclusion(0), any-list-inclusion(1), and professional-list-inclusion(2); its absence must be interpreted as no-list-inclusion by any directory consumer deriving mailing lists.

ldap, email

protocol-element §8.3.1

The pilotObject object class (pilotObjectClass 3) is a subclass of top that adds common optional attributes — info, photo, manager, uniqueIdentifier, lastModifiedTime, lastModifiedBy, dITRedirect, audio — usable by entries of any object class via subclassing.

ldap

protocol-element §8.3.2

The pilotPerson object class (pilotObjectClass 4) extends person with optional attributes including userid, rfc822Mailbox, homeTelephoneNumber, homePostalAddress, mobileTelephoneNumber, mailPreferenceOption, and personalSignature.

ldap, email

protocol-element §8.3.15

The qualityLabelledData object class (pilotObjectClass 22) allows assignment of data quality attributes to DIT subtrees; it requires dSAQuality and may include subtreeMinimumQuality and subtreeMaximumQuality.

ldap

protocol-element §8.3.12

The simpleSecurityObject object class (pilotObjectClass 19) is a subclass of top that allows any entry to carry a userPassword attribute when the entry's principal object classes do not permit it.

ldap, security

registry §7

The document establishes an OID hierarchy rooted at {ccitt 9 2342 19200300 100} (pilot), defining pilotAttributeType {pilot 1}, pilotAttributeSyntax {pilot 3}, pilotObjectClass {pilot 4}, and pilotGroups {pilot 10} as the namespace for all COSINE/Internet pilot schema definitions.

ldap, registry

security-consideration §3

Conformance to the schema requires support for the object classes and attribute types needed for X.509 strong authentication, including strongAuthenticationUser (userCertificate) and certificationAuthority (cACertificate, certificateRevocationList, authorityRevocationList, crossCertificatePair).

ldap, security, pkix

wire-format §9.4

DNSRecordSyntax is defined as IA5String with MATCHES FOR EQUALITY and is shared by aRecord, mXRecord, nSRecord, and sOARecord pilot attributes. NRSInformation syntax is a SET containing Context, Address-space-id, and routes (SEQUENCE OF Route-cost and Addressing-info).

ldap, dns

wire-format §9.3.18

The otherMailbox attribute (pilotAttributeType 22) is encoded as a SEQUENCE containing mailboxType (PrintableString, e.g., 'Telemail') and mailbox (IA5String, e.g., 'X378:Joe'), supporting non-X.400, non-RFC822 mailbox types.

ldap, email

wire-format §9.3.43

The personalSignature attribute (pilotAttributeType 53) is encoded identically to the photo attribute — a G3 facsimile body part per T.4 wrapped as an X.420 G3FacsimileBodyPart — with maximum size ub-personal-signature (50,000 octets).

ldap

wire-format §9.3.7

The photo attribute (pilotAttributeType 7) is encoded as a G3 facsimile body part per CCITT T.4, wrapped in an ASN.1 CHOICE to make it compatible with an X.400 G3FacsimileBodyPart from X.420; maximum size is ub-photo (250,000 octets).

ldap