What Is a Distinguished Name?
782
Netscape Certificate Management System Administrator’s Guide • June 2003
Distinguished Name Components
A DN identifies an entry in an LDAP directory. Because directories are
hierarchical, DNs identify the entry by its location as a path in a hierarchical tree
(much as a path in a file system identifies a file). Generally, a DN begins with a
specific common name, and proceeds with increasingly broader areas of
identification until the country name is specified. DNs are typically made up of the
following components (which are defined in the X.520 standard):
CN=common name, OU=organizational unit, O=organization, L=locality,
ST=state or province, C=country name
These components are described in Table I-1. For more information on
distinguished names, see RFC 2253 (which replaces RFC 1779). You can find RFC
2253 at this URL:
http://www.ietf.org/rfc/rfc2253.txt
Note that if used in conjunction with an LDAP-compliant directory, Certificate
Management System by default recognizes components that are listed in Table I-2.
Table I-1
Definitions of standard DN components
Component
Name
Definition
CN
Common name
A required component that identifies the person or object defined
by the entry. For example:
•
CN=Jane Doe
•
CN=corpDirectory.example.com
E
(deprecated)
Email address
Identifies the email address of the entry. For example:
The use of this component is discouraged by the PKIX standard;
instead, it recommends the use of Subject Alternative Name Extension
to associate an email address with a certificate; see
“subjectAltName” on page 766. The reason for this is because it is
usually too hard to have a
E
in a directory structure; email
addresses change too frequently.
OU
Organizational unit
Identifies a unit within the organization. For example:
•
OU=Sales
•
OU=Manufacturing
O
Organization
Identifies the organization in which the entry resides. For example:
•
O=Example Corporation
•
O=Public Power & Gas
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...