[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

AC509 Login Name



I am working on the use of attribute certificates for secure access to a
database, where the user's global identity authenticated using SSL/TLS needs
to be securely mapped to a local login name.

I presume that the Access Identity, as defined in 4.5.2 of
<draft-ietf-pkix-ac509prof-01>, can be used for this function.

However, I cannot find an existing name form defined in X.509 for
GeneralNames which could be used for a local login name.

Could one be defined as part of the IETF attribute certificate profile?

What syntax should this take?  A choice between UTF-8 and General Name would
be the simplest.

Nick Pope