5 # Includes LDAPv3 schema items from:
6 # RFC2251-RFC2256 (LDAPv3)
8 # select standard track schema items:
11 # RFC2247 (dc/dcObject)
12 # RFC2289 (Dynamic Directory Services)
14 # select informational schema items:
17 # select experimental IETF LDAPext items
20 # named referrals draft
24 # Standard X.501(93) Operational Attribute Types from RFC2252
26 attributetype ( 2.5.18.1 NAME 'createTimestamp' EQUALITY generalizedTimeMatch
27 ORDERING generalizedTimeOrderingMatch
28 SYNTAX 1.3.6.1.4.1.1466.115.121.1.24
29 SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )
31 attributetype ( 2.5.18.2 NAME 'modifyTimestamp' EQUALITY generalizedTimeMatch
32 ORDERING generalizedTimeOrderingMatch
33 SYNTAX 1.3.6.1.4.1.1466.115.121.1.24
34 SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )
36 attributetype ( 2.5.18.3 NAME 'creatorsName' EQUALITY distinguishedNameMatch
37 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12
38 SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )
40 attributetype ( 2.5.18.4 NAME 'modifiersName' EQUALITY distinguishedNameMatch
41 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12
42 SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )
44 attributetype ( 2.5.18.10 NAME 'subschemaSubentry'
45 EQUALITY distinguishedNameMatch
46 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 NO-USER-MODIFICATION
47 SINGLE-VALUE USAGE directoryOperation )
49 attributetype ( 2.5.21.5 NAME 'attributeTypes'
50 EQUALITY objectIdentifierFirstComponentMatch
51 SYNTAX 1.3.6.1.4.1.1466.115.121.1.3 USAGE directoryOperation )
53 attributetype ( 2.5.21.6 NAME 'objectClasses'
54 EQUALITY objectIdentifierFirstComponentMatch
55 SYNTAX 1.3.6.1.4.1.1466.115.121.1.37 USAGE directoryOperation )
57 attributetype ( 2.5.21.4 NAME 'matchingRules'
58 EQUALITY objectIdentifierFirstComponentMatch
59 SYNTAX 1.3.6.1.4.1.1466.115.121.1.30 USAGE directoryOperation )
61 attributetype ( 2.5.21.8 NAME 'matchingRuleUse'
62 EQUALITY objectIdentifierFirstComponentMatch
63 SYNTAX 1.3.6.1.4.1.1466.115.121.1.31 USAGE directoryOperation )
65 # LDAP Operational Attributes from RFC2252
67 attributetype ( 1.3.6.1.4.1.1466.101.120.5 NAME 'namingContexts'
68 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 USAGE dSAOperation )
70 attributetype ( 1.3.6.1.4.1.1466.101.120.6 NAME 'altServer'
71 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 USAGE dSAOperation )
73 attributetype ( 1.3.6.1.4.1.1466.101.120.7 NAME 'supportedExtension'
74 SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 USAGE dSAOperation )
76 attributetype ( 1.3.6.1.4.1.1466.101.120.13 NAME 'supportedControl'
77 SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 USAGE dSAOperation )
79 attributetype ( 1.3.6.1.4.1.1466.101.120.14 NAME 'supportedSASLMechanisms'
80 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 USAGE dSAOperation )
82 attributetype ( 1.3.6.1.4.1.1466.101.120.15 NAME 'supportedLDAPVersion'
83 SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 USAGE dSAOperation )
85 # LDAP Subschema Atrribute from RFC2252
87 attributetype ( 1.3.6.1.4.1.1466.101.120.16 NAME 'ldapSyntaxes'
88 EQUALITY objectIdentifierFirstComponentMatch
89 SYNTAX 1.3.6.1.4.1.1466.115.121.1.54 USAGE directoryOperation )
91 # X.500 Subschema attributes from RFC2252
93 attributetype ( 2.5.21.1 NAME 'dITStructureRules' EQUALITY integerFirstComponentMatch
94 SYNTAX 1.3.6.1.4.1.1466.115.121.1.17 USAGE directoryOperation )
96 attributetype ( 2.5.21.7 NAME 'nameForms'
97 EQUALITY objectIdentifierFirstComponentMatch
98 SYNTAX 1.3.6.1.4.1.1466.115.121.1.35 USAGE directoryOperation )
100 attributetype ( 2.5.21.2 NAME 'dITContentRules'
101 EQUALITY objectIdentifierFirstComponentMatch
102 SYNTAX 1.3.6.1.4.1.1466.115.121.1.16 USAGE directoryOperation )
104 # Object Classes from RFC2252
106 # extensibleObject moved forward, since it depends on top
107 # ldapSyntaxes (operational) is admissible in next:
109 objectclass ( 2.5.20.1 NAME 'subschema' AUXILIARY
110 MAY ( dITStructureRules $ nameForms $ ditContentRules $
111 objectClasses $ attributeTypes $ matchingRules $
114 # Standard attribute types from RFC2256
116 attributetype ( 2.5.4.0 NAME 'objectClass'
117 EQUALITY objectIdentifierMatch
118 SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 )
120 attributetype ( 2.5.4.1 NAME 'aliasedObjectName'
121 EQUALITY distinguishedNameMatch
122 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE )
124 # Defined, but no longer used
126 attributetype ( 2.5.4.2 NAME 'knowledgeInformation'
127 EQUALITY caseIgnoreMatch
128 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} )
130 # Place here since other attribute types derive from it
132 attributetype ( 2.5.4.41 NAME 'name'
133 EQUALITY caseIgnoreMatch
134 SUBSTR caseIgnoreSubstringsMatch
135 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} )
137 attributetype ( 2.5.4.3 NAME ( 'cn' 'commonName' ) SUP name )
139 attributetype ( 2.5.4.4 NAME ( 'sn' 'surname' ) SUP name )
141 attributetype ( 2.5.4.5 NAME 'serialNumber' EQUALITY caseIgnoreMatch
142 SUBSTR caseIgnoreSubstringsMatch
143 SYNTAX 1.3.6.1.4.1.1466.115.121.1.44{64} )
145 # (2-letter code from ISO 3166)
147 attributetype ( 2.5.4.6 NAME ( 'c' 'countryName' ) SUP name SINGLE-VALUE )
149 attributetype ( 2.5.4.7 NAME ( 'l' 'localityName' ) SUP name )
151 attributetype ( 2.5.4.8 NAME ( 'st' 'stateOrProvinceName' ) SUP name )
153 attributetype ( 2.5.4.9 NAME ( 'street' 'streetAddress' )
154 EQUALITY caseIgnoreMatch
155 SUBSTR caseIgnoreSubstringsMatch
156 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} )
158 attributetype ( 2.5.4.10 NAME ( 'o' 'organizationName' ) SUP name )
160 attributetype ( 2.5.4.11 NAME ( 'ou' 'organizationalUnitName' ) SUP name )
162 attributetype ( 2.5.4.12 NAME 'title' SUP name )
164 attributetype ( 2.5.4.13 NAME 'description'
165 EQUALITY caseIgnoreMatch
166 SUBSTR caseIgnoreSubstringsMatch
167 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1024} )
169 # Obsoleted by enhancedSearchGuide
171 attributetype ( 2.5.4.14 NAME 'searchGuide'
172 SYNTAX 1.3.6.1.4.1.1466.115.121.1.25 )
174 attributetype ( 2.5.4.15 NAME 'businessCategory'
175 EQUALITY caseIgnoreMatch
176 SUBSTR caseIgnoreSubstringsMatch
177 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} )
179 attribute ( 2.5.4.16 NAME 'postalAddress'
180 EQUALITY caseIgnoreListMatch
181 SUBSTR caseIgnoreListSubstringsMatch
182 SYNTAX 1.3.6.1.4.1.1466.115.121.1.41 )
184 attributetype ( 2.5.4.17 NAME 'postalCode'
185 EQUALITY caseIgnoreMatch
186 SUBSTR caseIgnoreSubstringsMatch
187 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{40} )
189 attributetype ( 2.5.4.18 NAME 'postOfficeBox'
190 EQUALITY caseIgnoreMatch
191 SUBSTR caseIgnoreSubstringsMatch
192 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{40} )
194 attributetype ( 2.5.4.19 NAME 'physicalDeliveryOfficeName'
195 EQUALITY caseIgnoreMatch
196 SUBSTR caseIgnoreSubstringsMatch
197 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} )
199 attributetype ( 2.5.4.20 NAME 'telephoneNumber'
200 EQUALITY telephoneNumberMatch
201 SUBSTR telephoneNumberSubstringsMatch
202 SYNTAX 1.3.6.1.4.1.1466.115.121.1.50{32} )
204 attributetype ( 2.5.4.21 NAME 'telexNumber'
205 SYNTAX 1.3.6.1.4.1.1466.115.121.1.52 )
207 attributetype ( 2.5.4.22 NAME 'teletexTerminalIdentifier'
208 SYNTAX 1.3.6.1.4.1.1466.115.121.1.51 )
210 attributetype ( 2.5.4.23 NAME ( 'facsimileTelephoneNumber' 'fax' )
211 SYNTAX 1.3.6.1.4.1.1466.115.121.1.22 )
213 attributetype ( 2.5.4.24 NAME 'x121Address'
214 EQUALITY numericStringMatch
215 SUBSTR numericStringSubstringsMatch
216 SYNTAX 1.3.6.1.4.1.1466.115.121.1.36{15} )
218 attributetype ( 2.5.4.25 NAME 'internationaliSDNNumber'
219 EQUALITY numericStringMatch
220 SUBSTR numericStringSubstringsMatch
221 SYNTAX 1.3.6.1.4.1.1466.115.121.1.36{16} )
223 attributetype ( 2.5.4.26 NAME 'registeredAddress' SUP postalAddress
224 SYNTAX 1.3.6.1.4.1.1466.115.121.1.41 )
226 attributetype ( 2.5.4.27 NAME 'destinationIndicator'
227 EQUALITY caseIgnoreMatch
228 SUBSTR caseIgnoreSubstringsMatch
229 SYNTAX 1.3.6.1.4.1.1466.115.121.1.44{128} )
231 attributetype ( 2.5.4.28 NAME 'preferredDeliveryMethod'
232 SYNTAX 1.3.6.1.4.1.1466.115.121.1.14
235 attributetype ( 2.5.4.29 NAME 'presentationAddress'
236 EQUALITY presentationAddressMatch
237 SYNTAX 1.3.6.1.4.1.1466.115.121.1.43
240 attributetype ( 2.5.4.30 NAME 'supportedApplicationContext'
241 EQUALITY objectIdentifierMatch
242 SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 )
244 # Placed here because others derive from it.
246 # We had a dn definition in slapd.at.conf and Netscape lists both
247 # names for that OID. This is wrong, 'dn' is used internally in slapd
248 # as the name of a pseudo-attribute type that contains the
249 # distinguished name of an entry. On the other hand, the attribute
250 # type distinguishedName is meant to be an "abstract" type and other
251 # dn-valued attribute types derive from it. So at most, 'dn' would
252 # be a subtype of distinguishedName, something like:
253 # attributetype ( dnOID NAME 'dn' SUP distinguishedName
254 # SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )
256 attributetype ( 2.5.4.49 NAME 'distinguishedName'
257 EQUALITY distinguishedNameMatch
258 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
260 attributetype ( 2.5.4.31 NAME 'member' SUP distinguishedName )
262 attributetype ( 2.5.4.32 NAME 'owner' SUP distinguishedName )
264 attributetype ( 2.5.4.33 NAME 'roleOccupant' SUP distinguishedName )
266 attributetype ( 2.5.4.34 NAME 'seeAlso' SUP distinguishedName )
268 attributetype ( 2.5.4.35 NAME 'userPassword'
269 EQUALITY octetStringMatch
270 SYNTAX 1.3.6.1.4.1.1466.115.121.1.40{128} )
272 # Must be stored and requested in the binary form, as
273 # userCertificate;binary
274 attributetype ( 2.5.4.36 NAME 'userCertificate'
275 SYNTAX 1.3.6.1.4.1.1466.115.121.1.8 )
278 attributetype ( 2.5.4.37 NAME 'cACertificate'
279 SYNTAX 1.3.6.1.4.1.1466.115.121.1.8 )
282 attributetype ( 2.5.4.38 NAME 'authorityRevocationList'
283 SYNTAX 1.3.6.1.4.1.1466.115.121.1.9 )
286 attributetype ( 2.5.4.39 NAME 'certificateRevocationList'
287 SYNTAX 1.3.6.1.4.1.1466.115.121.1.9 )
290 attributetype ( 2.5.4.40 NAME 'crossCertificatePair'
291 SYNTAX 1.3.6.1.4.1.1466.115.121.1.10 )
293 # 2.5.4.41 is 'name', moved above since other attribute types derive from it
295 attributetype ( 2.5.4.42 NAME ( 'givenName' 'gn' ) SUP name )
297 attributetype ( 2.5.4.43 NAME 'initials' SUP name )
299 attributetype ( 2.5.4.45 NAME 'x500UniqueIdentifier'
300 EQUALITY bitStringMatch
301 SYNTAX 1.3.6.1.4.1.1466.115.121.1.6 )
303 attributetype ( 2.5.4.46 NAME 'dnQualifier'
304 EQUALITY caseIgnoreMatch
305 ORDERING caseIgnoreOrderingMatch
306 SUBSTR caseIgnoreSubstringsMatch
307 SYNTAX 1.3.6.1.4.1.1466.115.121.1.44 )
309 attributetype ( 2.5.4.47 NAME 'enhancedSearchGuide'
310 SYNTAX 1.3.6.1.4.1.1466.115.121.1.21 )
312 attributetype ( 2.5.4.48 NAME 'protocolInformation'
313 EQUALITY protocolInformationMatch
314 SYNTAX 1.3.6.1.4.1.1466.115.121.1.42 )
316 # 2.5.4.49 is distinguishedName, moved up
318 attributetype ( 2.5.4.50 NAME 'uniqueMember'
319 EQUALITY uniqueMemberMatch
320 SYNTAX 1.3.6.1.4.1.1466.115.121.1.34 )
322 attributetype ( 2.5.4.51 NAME 'houseIdentifier'
323 EQUALITY caseIgnoreMatch
324 SUBSTR caseIgnoreSubstringsMatch
325 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} )
327 # This attribute is to be stored and requested in the binary form, as
328 # 'supportedAlgorithms;binary'.
330 attributetype ( 2.5.4.52 NAME 'supportedAlgorithms'
331 SYNTAX 1.3.6.1.4.1.1466.115.121.1.49 )
333 # This attribute is to be stored and requested in the binary form, as
334 # 'deltaRevocationList;binary'.
336 attributetype ( 2.5.4.53 NAME 'deltaRevocationList'
337 SYNTAX 1.3.6.1.4.1.1466.115.121.1.9 )
339 attributetype ( 2.5.4.54 NAME 'dmdName' SUP name )
341 # Standard object classes from RFC2256
343 objectclass ( 2.5.6.0 NAME 'top' ABSTRACT
346 objectclass ( 2.5.6.1 NAME 'alias' SUP top STRUCTURAL
347 MUST aliasedObjectName )
349 objectclass ( 2.5.6.2 NAME 'country' SUP top STRUCTURAL
351 MAY ( searchGuide $ description ) )
353 objectclass ( 2.5.6.3 NAME 'locality' SUP top STRUCTURAL
354 MAY ( street $ seeAlso $ searchGuide $ st $ l $ description ) )
356 objectclass ( 2.5.6.4 NAME 'organization' SUP top STRUCTURAL
358 MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $
359 x121Address $ registeredAddress $ destinationIndicator $
360 preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
361 telephoneNumber $ internationaliSDNNumber $
362 facsimileTelephoneNumber $
363 street $ postOfficeBox $ postalCode $ postalAddress $
364 physicalDeliveryOfficeName $ st $ l $ description ) )
366 objectclass ( 2.5.6.5 NAME 'organizationalUnit' SUP top STRUCTURAL
368 MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $
369 x121Address $ registeredAddress $ destinationIndicator $
370 preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
371 telephoneNumber $ internationaliSDNNumber $
372 facsimileTelephoneNumber $
373 street $ postOfficeBox $ postalCode $ postalAddress $
374 physicalDeliveryOfficeName $ st $ l $ description ) )
376 objectclass ( 2.5.6.6 NAME 'person' SUP top STRUCTURAL
378 MAY ( userPassword $ telephoneNumber $ seeAlso $ description ) )
380 objectclass ( 2.5.6.7 NAME 'organizationalPerson' SUP person STRUCTURAL
381 MAY ( title $ x121Address $ registeredAddress $
382 destinationIndicator $
383 preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
384 telephoneNumber $ internationaliSDNNumber $
385 facsimileTelephoneNumber $
386 street $ postOfficeBox $ postalCode $ postalAddress $
387 physicalDeliveryOfficeName $ ou $ st $ l ) )
389 # Notice that preferredDeliveryMethod is duplicate
391 objectclass ( 2.5.6.8 NAME 'organizationalRole' SUP top STRUCTURAL
393 MAY ( x121Address $ registeredAddress $ destinationIndicator $
394 preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
395 telephoneNumber $ internationaliSDNNumber $
396 facsimileTelephoneNumber $
397 seeAlso $ roleOccupant $ preferredDeliveryMethod $ street $
398 postOfficeBox $ postalCode $ postalAddress $
399 physicalDeliveryOfficeName $ ou $ st $ l $ description ) )
401 objectclass ( 2.5.6.9 NAME 'groupOfNames' SUP top STRUCTURAL
403 MAY ( businessCategory $ seeAlso $ owner $ ou $ o $ description ) )
405 # Notice that preferredDeliveryMethod is duplicate
406 # It seems they could not agree on whether telephoneNumber is MAY
407 # in person. Probably it wasn't originally at was added as an
410 objectclass ( 2.5.6.10 NAME 'residentialPerson' SUP person STRUCTURAL
412 MAY ( businessCategory $ x121Address $ registeredAddress $
413 destinationIndicator $ preferredDeliveryMethod $ telexNumber $
414 teletexTerminalIdentifier $ telephoneNumber $
415 internationaliSDNNumber $
416 facsimileTelephoneNumber $ preferredDeliveryMethod $ street $
417 postOfficeBox $ postalCode $ postalAddress $
418 physicalDeliveryOfficeName $ st $ l ) )
420 objectclass ( 2.5.6.11 NAME 'applicationProcess' SUP top STRUCTURAL
422 MAY ( seeAlso $ ou $ l $ description ) )
424 objectclass ( 2.5.6.12 NAME 'applicationEntity' SUP top STRUCTURAL
425 MUST ( presentationAddress $ cn )
426 MAY ( supportedApplicationContext $ seeAlso $ ou $ o $ l $
429 # This one was wrong in our schema, it only allowed the aditional
430 # knowledgeInformation attribute, while it is derived from
431 # applicationEntity and should allow all its attributes as well.
433 objectclass ( 2.5.6.13 NAME 'dSA' SUP applicationEntity STRUCTURAL
434 MAY knowledgeInformation )
436 objectclass ( 2.5.6.14 NAME 'device' SUP top STRUCTURAL
438 MAY ( serialNumber $ seeAlso $ owner $ ou $ o $ l $ description ) )
440 objectclass ( 2.5.6.15 NAME 'strongAuthenticationUser' SUP top AUXILIARY
441 MUST userCertificate )
443 objectclass ( 2.5.6.16 NAME 'certificationAuthority' SUP top AUXILIARY
444 MUST ( authorityRevocationList $ certificateRevocationList $
445 cACertificate ) MAY crossCertificatePair )
449 objectclass ( 2.5.6.17 NAME 'groupOfUniqueNames' SUP top STRUCTURAL
450 MUST ( uniqueMember $ cn )
451 MAY ( businessCategory $ seeAlso $ owner $ ou $ o $ description ) )
455 objectclass ( 2.5.6.18 NAME 'userSecurityInformation' SUP top AUXILIARY
456 MAY ( supportedAlgorithms ) )
460 objectclass ( 2.5.6.16.2 NAME 'certificationAuthority-V2' SUP
461 certificationAuthority
462 AUXILIARY MAY ( deltaRevocationList ) )
466 objectclass ( 2.5.6.19 NAME 'cRLDistributionPoint' SUP top STRUCTURAL
468 MAY ( certificateRevocationList $ authorityRevocationList $
469 deltaRevocationList ) )
473 objectclass ( 2.5.6.20 NAME 'dmd' SUP top STRUCTURAL
475 MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $
476 x121Address $ registeredAddress $ destinationIndicator $
477 preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
478 telephoneNumber $ internationaliSDNNumber $
479 facsimileTelephoneNumber $
480 street $ postOfficeBox $ postalCode $ postalAddress $
481 physicalDeliveryOfficeName $ st $ l $ description ) )
483 # Next objectclass is defined in RFC2252, but has to be put after top
485 objectclass ( 1.3.6.1.4.1.1466.101.120.111 NAME 'extensibleObject'
486 DESC 'RFC2252 extensible object'
490 # Standard Track URI label schema from RFC2079
492 attributetype ( 1.3.6.1.4.1.250.1.57 NAME 'labeledURI'
493 DESC 'Uniform Resource Identifier with optional label'
494 EQUALITY caseExactIA5Match
495 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
497 objectclass ( 1.3.6.1.4.1.250.3.15 NAME 'labeledURIObject'
498 DESC 'object that contains the URI attribute type'
503 # Standard Track Dynamic Directory Services from RFC2589
505 objectclass ( 1.3.6.1.4.1.1466.101.119.2 NAME 'dynamicObject'
506 DESC 'RFC2589 Dynamic Object'
509 attributetype ( 1.3.6.1.4.1.1466.101.119.3 NAME 'entryTtl'
510 DESC 'RFC2589 entry time-to-live'
511 SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE
512 NO-USER-MODIFICATION USAGE dSAOperation )
514 attributetype ( 1.3.6.1.4.1.1466.101.119.4 NAME 'dynamicSubtrees'
515 DESC 'RFC2589 dynamic subtrees'
516 SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 NO-USER-MODIFICATION
519 # Derived from RFC1274, but with new "short names"
520 attributetype ( 0.9.2342.19200300.100.1.1
521 NAME ( 'uid' 'userid' )
522 DESC 'RFC1274 user identifier'
523 EQUALITY caseIgnoreMatch
524 SUBSTR caseIgnoreSubstringsMatch
525 SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
527 attributetype ( 0.9.2342.19200300.100.1.3 NAME ( 'mail' 'rfc822Mailbox' )
528 DESC 'rfc822 mail box'
529 EQUALITY caseIgnoreIA5Match
530 SUBSTR caseIgnoreIA5SubstringsMatch
531 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256} )
533 objectclass ( 0.9.2342.19200300.100.4.19 NAME 'simpleSecurityObject'
539 attributetype ( 0.9.2342.19200300.100.1.25
540 NAME ( 'dc' 'domainComponent' )
541 DESC 'RFC1274/2247 domain component'
542 EQUALITY caseIgnoreIA5Match
543 SUBSTR caseIgnoreIA5SubstringsMatch
544 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE )
547 objectclass ( 1.3.6.1.4.1.1466.344 NAME 'dcObject'
548 SUP top AUXILIARY MUST dc )
552 objectclass ( 1.3.6.1.1.3.1 NAME 'uidObject'
553 DESC 'RFC2377 uid object'
554 SUP top AUXILIARY MUST uid )
557 # From draft-ietf-ldapext-nameref-00.txt
558 # used to represent referrals in the directory
560 attributetype ( 2.16.840.1.113730.3.1.34 NAME 'ref'
561 DESC 'Named referral'
562 EQUALITY caseExactIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26
563 USAGE distributedOperation )
565 objectclass ( 2.16.840.1.113730.3.2.6 NAME 'referral'
566 DESC 'Named referral object'
567 SUP top STRUCTURAL MAY ref )
572 objectclass ( 2.16.840.1.113719.2.142.6.1.1 NAME 'LDAPsubEntry'
574 SUP top STRUCTURAL MAY cn )
579 objectclass ( 1.3.6.1.4.1.4203.666.3.2
580 NAME ( 'OpenLDAProotDSE' 'LDAProotDSE' )
581 DESC 'OpenLDAP Root DSE object'
582 SUP top STRUCTURAL MAY cn )
588 attributetype ( 1.3.6.1.4.1.250.1.32
589 NAME ( 'krbName' 'kerberosName' )
591 EQUALITY caseIgnoreIA5Match
592 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26
597 # OpenLDAP specific schema items
599 attributetype ( 1.3.6.1.4.1.4203.666.1.1
601 DESC 'OpenLDAP authPassword attribute'
602 EQUALITY authPasswordMatch
603 SYNTAX 1.3.6.1.4.1.4203.666.2.2
606 attributetype ( 1.3.6.1.4.1.4203.666.1.2
607 NAME 'supportedAuthPasswordSchemes'
608 DESC 'OpenLDAP authPassword attribute'
609 EQUALITY caseIgnoreIA5Match
610 SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32}
611 NO-USER-MODIFICATION USAGE dSAOperation )
613 attributetype ( 1.3.6.1.4.1.4203.666.1.3
615 DESC 'OpenLDAP ACL entry psuedo attribute'
616 SYNTAX 1.3.6.1.4.1.4203.666.2.3
617 SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )
619 attributetype ( 1.3.6.1.4.1.4203.666.1.4
621 DESC 'OpenLDAP ACL children psuedo attribute'
622 SYNTAX 1.3.6.1.4.1.4203.666.2.3
623 SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )
625 attributetype ( 1.3.6.1.4.1.4203.666.1.5
627 DESC 'OpenLDAP access control information'
628 EQUALITY OpenLDAPaciMatch
629 SYNTAX 1.3.6.1.4.1.4203.666.2.1
630 USAGE directoryOperation )
632 objectclass ( 1.3.6.1.4.1.4203.666.3.1 NAME 'authPasswordObject'
633 DESC 'authentication password mixin class'