Shyh-Wei, I think that, for organizational persons, a second component for the terminal RDN would usually be something that those managing the local namespace would see as natural, i.e., it is something like an employee ID number that has already been assigned and thus is not an arbitrary string like the Subject UID. Steve