80 likes | 234 Views
TrustCoM Project http://www.eu-trustcom.com/. LDAP PKI and PMI Schemas. d.w.chadwick@salford.ac.uk. 3 IDs in the series. Internet X.509 Public Key Infrastructure LDAP Schema for X.509 CRLs <draft-ietf-pkix-ldap-crl-schema-02.txt>
E N D
TrustCoM Project http://www.eu-trustcom.com/ LDAP PKI and PMI Schemas d.w.chadwick@salford.ac.uk TrustCoM Project University of Salford
3 IDs in the series • Internet X.509 Public Key Infrastructure LDAP Schema for X.509 CRLs <draft-ietf-pkix-ldap-crl-schema-02.txt> • Internet X.509 Public Key Infrastructure LDAP Schema for X.509 Attribute Certificates <draft-ietf-pkix-ldap-ac-schema-01.txt> • Internet X.509 Public Key Infrastructure LDAP Schema for X.509 Certificates <draft-ietf-pkix-ldap-pkc-schema-00 ALL DESTINED FOR INFORMATIONAL RFCS TrustCoM Project University of Salford
[ ] Attribute Extraction LDAP directory XPS server + Search for Att 1.. Att i Return X.509 attribute Att1, Att2…Att n CA/AA TrustCoM Project University of Salford
The DIT Structure • PKCs and ACs are held in child entries • CRLs are held in child subtrees dc=com dc=myorg dc=com dc=myorg ou=My CA ou=people CRL AC containing roles cn=my entry Encryption PKC CRL entries Signing PKC serialno=nnnn + issuer=‘ou=MyCA,dc=myorg,dc=com’ TrustCoM Project University of Salford
Implementation Details • Implemented in OpenLDAP 2.2.11 and newer • Code is not in the main branch yet since it's being reviewed by OpenLDAP programmers TrustCoM Project University of Salford
LDAP Client view of XPS TrustCoM Project University of Salford
Way Forward • Latest versions • Added IANA considerations and acks, re-arranged object classes, aligned all 3 IDs, minor corrections • Outstanding Issues • None • WG Last Call ?? Is it needed for an Inf RFC • Ready to go now TrustCoM Project University of Salford
Other LDAP work • V3 Profile TrustCoM Project University of Salford