| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293 |
- <!-- --- BEGIN COPYRIGHT BLOCK ---
- This Program is free software; you can redistribute it and/or modify it under
- the terms of the GNU General Public License as published by the Free Software
- Foundation; version 2 of the License.
- This Program is distributed in the hope that it will be useful, but WITHOUT
- ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
- FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
- You should have received a copy of the GNU General Public License along with
- this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
- Place, Suite 330, Boston, MA 02111-1307 USA.
- In addition, as a special exception, Red Hat, Inc. gives You the additional
- right to link the code of this Program with code not covered under the GNU
- General Public License ("Non-GPL Code") and to distribute linked combinations
- including the two, subject to the limitations in this paragraph. Non-GPL Code
- permitted under this exception must only link to the code of this Program
- through those well defined interfaces identified in the file named EXCEPTION
- found in the source code files (the "Approved Interfaces"). The files of
- Non-GPL Code may instantiate templates or use macros or inline functions from
- the Approved Interfaces without causing the resulting work to be covered by
- the GNU General Public License. Only Red Hat, Inc. may make changes or
- additions to the list of Approved Interfaces. You must obey the GNU General
- Public License in all respects for all of the Program code and other code used
- in conjunction with the Program except the Non-GPL Code covered by this
- exception. If you modify this file, you may extend this exception to your
- version of the file, but you are not obligated to do so. If you do not wish to
- provide this exception without modification, you must delete this exception
- statement from your version and license this file solely under the GPL without
- exception.
-
- Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
- Copyright (C) 2005 Red Hat, Inc.
- All rights reserved.
- --- END COPYRIGHT BLOCK --- -->
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
- <HTML>
- <HEAD>
- <TITLE></TITLE>
- <META NAME="GENERATOR" CONTENT="Mozilla/3.0b6Gold (WinNT; I) [Netscape]">
- </HEAD>
- <BODY>
- <P><A NAME="1001595"></A></P>
- <P><A NAME="1001596"></A></P>
- <P><A NAME="996824"></A></P>
- <H1>Distinguished Names</H1>
- <P><A NAME="1017708"></A>Distinguished
- Names (DNs) are the string representation for entry names in the Directory
- Server database. You use DNs to name entries when you add entries to the
- directory, add members to groups, etc..</P>
- <P><A NAME="1017709"></A>A DN can consist of virtually any attributes you
- wish to use. The only caveat is that if schema checking is turned on, then
- the attributes must be recognized by the Directory Server (if you do not
- know whether schema checking is turned on in the server, contact your directory
- manager, or consult the <I>Netscape Directory Server Administrator's Guide</I>
- for more information).</P>
- <P><A NAME="1017710"></A>Traditionally, a DN consists of:</P>
- <UL>
- <P><A NAME="1017711"></A></P>
- <LI>A common name followed by<A NAME="1017712"></A></LI>
- <LI>a list of regional or organizational attributes followed by<A NAME="1017713"></A></LI>
- <LI>a country designation.</LI>
- </UL>
- <P><A NAME="1017714"></A>This string of identifying attributes uniquely
- locates the entry within your Directory Server database. If you choose,
- you can also use this naming structure to uniquely identify your entries
- within the global directory tree as defined in the X.500 standard.</P>
- <P><A NAME="1017715"></A>Because a DN represents a path through the directory
- tree, the DN components are order-dependent. For example, the following
- DNs do not represent the same entry:</P>
- <P><A NAME="1017716"></A></P>
- <PRE> cn=Ralph Swenson, ou=Accounting, o=Example Corp, c=US
- cn=Ralph Swenson, o=Example Corp, ou=Accounting, c=US
- </PRE>
- <P><A NAME="Distinguished Name syntax"></A><A NAME="1017717"></A></P>
- <H2>Distinguished Name syntax</H2>
- <P><A NAME="1017718"></A>The traditional syntax for a DN string representation
- is as follows:</P>
- <P><A NAME="1017719"></A></P>
- <UL>
- <PRE>cn=<I>common name</I>, [street=<I>address</I>, l=<I>locality</I>, st = <I>state or province</I>,
- ou=<I>organizational unit</I>, o=<I>organization</I>], c=<I>country name</I>
- </PRE>
- </UL>
- <P><A NAME="1017720"></A>Generally a DN begins with a specific common name,
- and proceeds with increasingly broader areas of identification until the
- country name is specified. Note, however, that the actual DN attributes
- you use, and the order in which you choose to specify them, is up to you
- and how you want to organize your database. The only real requirement is
- that DN attributes must be separated by a comma (,) and can optionally
- use a space ( ) following the separator.</P>
- <P><A NAME="Distinguished Name attributes"></A><A NAME="1017721"></A></P>
- <H2>Distinguished Name attributes</H2>
- <P><A NAME="1017792"></A>The various standard attributes that comprise
- a DN are as follows:</P>
- <TABLE BORDER=2 >
- <CAPTION></CAPTION>
- <TR>
- <TH><A NAME="1017730"></A><B>Attribute</B></TH>
- <TH><A NAME="1017732"></A><B>Name</B></TH>
- <TH><A NAME="1017734"></A><B>Definition</B></TH>
- </TR>
- <TR>
- <TD><A NAME="1017736"></A>c</TD>
- <TD><A NAME="1017738"></A>country</TD>
- <TD><A NAME="1017740"></A>Identifies the name of the country under which
- the entry resides. For example,
- <UL>
- <P><A NAME="1017741"></A></P>
- <LI>c=US<A NAME="1017742"></A></LI>
- <LI>c=GB</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017744"></A>cn</TD>
- <TD><A NAME="1017746"></A>common name</TD>
- <TD><A NAME="1017748"></A>Required attribute that identifies the person
- or object defined by the entry. For example:
- <UL>
- <P><A NAME="1017749"></A></P>
- <LI>cn=Wally Henderson<A NAME="1017750"></A></LI>
- <LI>cn=Database Administrators<A NAME="1017751"></A></LI>
- <LI>cn=printer3b</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017753"></A>l</TD>
- <TD><A NAME="1017755"></A>locality</TD>
- <TD><A NAME="1017757"></A>Identifies the locality in which the entry resides.
- The locality could be a city, county, township, or other geographic region.
- For example:
- <UL>
- <P><A NAME="1017758"></A></P>
- <LI>l=Tucson<A NAME="1017759"></A></LI>
- <LI>l=Pacific Northwest<A NAME="1017760"></A></LI>
- <LI>l=Anoka County</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017762"></A>o</TD>
- <TD><A NAME="1017764"></A>organization</TD>
- <TD><A NAME="1017766"></A>Identifies the organization in which the entry
- resides. For example:
- <UL>
- <P><A NAME="1017767"></A></P>
- <LI>o=Netscape Communications Corp<A NAME="1017768"></A></LI>
- <LI>o=Public Power & Gas</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017770"></A>ou</TD>
- <TD><A NAME="1017772"></A>organizational unit</TD>
- <TD><A NAME="1017774"></A>Identifies a unit within the organization. For
- example:
- <UL>
- <P><A NAME="1017775"></A></P>
- <LI>ou=Sales<A NAME="1017776"></A></LI>
- <LI>ou=Manufacturing</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017778"></A>st</TD>
- <TD><A NAME="1017780"></A>state or province name</TD>
- <TD><A NAME="1017782"></A>Identifies the state or province in which the
- entry resides. For example:
- <UL>
- <P><A NAME="1017783"></A></P>
- <LI>st=Iowa<A NAME="1017784"></A></LI>
- <LI>st=British Columbia</LI>
- </UL>
- </TD>
- </TR>
- <TR>
- <TD><A NAME="1017786"></A>street</TD>
- <TD><A NAME="1017788"></A>street address</TD>
- <TD><A NAME="1017790"></A>Identifies the street address at which the entry
- resides. For example:
- <UL>
- <P><A NAME="1017791"></A></P>
- <LI>street=494 Rice Creek Terrace</LI>
- </UL>
- </TD>
- </TR>
- </TABLE>
- <TABLE>
- <TR>
- <TD></TD>
- </TR>
- </TABLE>
- <P><A NAME="Distinguished Name examples"></A><A NAME="1017793"></A></P>
- <H2>Distinguished Name examples</H2>
- <P><A NAME="1017794"></A>The following are some examples of DNs:</P>
- <P><A NAME="1017795"></A></P>
- <UL>
- <PRE>cn=Wally Henderson,ou=Product Development,o=Example Corp,st=Minnesota,c=US
- </PRE>
- </UL>
- <P><A NAME="1017796"></A></P>
- <UL>
- <PRE>cn=Retch Sweeny, ou=Product Test, o=Example Corp, st=Michigan, c=US
- </PRE>
- </UL>
- <P><A NAME="1017797"></A></P>
- <UL>
- <PRE>cn=printer3b, l=room 308, o=Example Corp, c=US
- </PRE>
- </UL>
- <P><A NAME="997436"></A></P>
- </BODY>
- </HTML>
|