DESC ’Destination IP address’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcelsIPHdrDestAddressEndOfRange attribute type represents the end
of a range of destination IP addresses. It is mapped from the
IpHeadersFilter.HdrDestAddressEndOfRange property [PCIM_EXT]. This
attribute type is of syntax OctetString [LDAP_SYNTAX]. It has an
equality matching rule of octetStringMatch [LDAP_SCHEMA] and an
ordering matching rule of octetStringOrderingMatch [LDAP_MATCH].
Attributes of this type can only have a single value. The only
allowed values for attributes of this type are octet strings with a
size of 4, 16, or 20.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.39
NAME ’pcelsIPHdrDestAddressEndOfRange’
DESC ’End of a range of destination IP addresses’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcelsIPHdrDestMask attribute type represents a mask to be used in
comparing the destination IP address. It is mapped from the
IpHeadersFilter.HdrDestMask property [PCIM_EXT]. This attribute type
is of syntax OctetString [LDAP_SYNTAX]. It has an equality matching
rule of octetStringMatch [LDAP_SCHEMA] and an ordering matching rule
of octetStringOrderingMatch [LDAP_MATCH]. Attributes of this type
can only have a single value. The only allowed values for attributes
of this type are octet strings with a size of 4, 16, or 20.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.40
NAME ’pcelsIPHdrDestMask’
DESC ’Mask to be used in comparing the destination IP address’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcelsIPHdrProtocolID attribute type indicates an IP protocol
type. It is mapped from the IpHeadersFilter.HdrProtocolID property
[PCIM_EXT]. This attribute type is of syntax Integer [LDAP_SYNTAX].
It has an equality matching rule of integerMatch [LDAP_SYNTAX] and an
ordering matching rule of integerOrderingMatch [LDAP_MATCH].
Attributes of this type can only have a single value. The only
allowed values for attributes of this type are integers in the range
0..255 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.41
NAME ’pcelsIPHdrProtocolID’
DESC ’IP protocol type’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsIPHdrSourcePortStart attribute type represents the lower end
of a range of UDP or TCP source ports. It is mapped from the
IpHeadersFilter.HdrSrcPortStart property [PCIM_EXT]. This attribute
type is of syntax Integer [LDAP_SYNTAX]. It has an equality matching
rule of integerMatch [LDAP_SYNTAX] and an ordering matching rule of
integerOrderingMatch [LDAP_MATCH]. Attributes of this type can only
have a single value. The only allowed values for attributes of this
type are integers in the range 0..65535 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.42
NAME ’pcelsIPHdrSourcePortStart’
DESC ’Lower end of a range of UDP or TCP source ports’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsIPHdrSourcePortEnd attribute type represents the upper end
of a range of UDP or TCP source ports. It is mapped from the
IpHeadersFilter.HdrSrcPortEnd property [PCIM_EXT]. This attribute
type is of syntax Integer [LDAP_SYNTAX]. It has an equality matching
rule of integerMatch [LDAP_SYNTAX] and an ordering matching rule of
integerOrderingMatch [LDAP_MATCH]. Attributes of this type can only
have a single value. The only allowed values for attributes of this
type are integers in the range 0..65535 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.43
NAME ’pcelsIPHdrSourcePortEnd’
DESC ’Upper end of a range of UDP or TCP source ports’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsIPHdrDestPortStart attribute type represents the lower end
of a range of UDP or TCP destination ports. It is mapped from the
IpHeadersFilter.HdrDestPortStart property [PCIM_EXT]. This attribute
type is of syntax Integer [LDAP_SYNTAX]. It has an equality matching
rule of integerMatch [LDAP_SYNTAX] and an ordering matching rule of
integerOrderingMatch [LDAP_MATCH]. Attributes of this type can only
have a single value. The only allowed values for attributes of this
type are integers in the range 0..65535 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.44
NAME ’pcelsIPHdrDestPortStart’
DESC ’Lower end of a range of UDP or TCP destination ports’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsIPHdrDestPortEnd attribute type represents the upper end of
a range of UDP or TCP destination ports. It is mapped from the
IpHeadersFilter.HdrDestPortEnd property [PCIM_EXT]. This attribute
type is of syntax Integer [LDAP_SYNTAX]. It has an equality matching
rule of integerMatch [LDAP_SYNTAX] and an ordering matching rule of
integerOrderingMatch [LDAP_MATCH]. Attributes of this type can only
have a single value. The only allowed values for attributes of this
type are integers in the range 0..65535 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.45
NAME ’pcelsIPHdrDestPortEnd’
DESC ’Upper end of a range of UDP or TCP destination ports’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsIPHdrDSCPList attribute type is mapped from the
IpHeadersFilter.HdrDSCP property [PCIM_EXT]. This attribute type is
of syntax Integer [LDAP_SYNTAX]. It has an equality matching rule of
integerMatch [LDAP_SYNTAX] and an ordering matching rule of
integerOrderingMatch [LDAP_MATCH]. Attributes of this type can have
multiple values. The only allowed values for attributes of this type
are integers in the range 0..63 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.46
NAME ’pcelsIPHdrDSCPList’
DESC ’DSCP values’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
)
The pcelsIPHdrFlowLabel attribute type is mapped from the
IpHeadersFilter.HdrFlowLabel property [PCIM_EXT]. This attribute
type is of syntax OctetString [LDAP_SYNTAX]. It has an equality
matching rule of octetStringMatch [LDAP_SCHEMA] and an ordering
matching rule of octetStringOrderingMatch [LDAP_MATCH]. Attributes
of this type can only have a single value. The only allowed values
for attributes of this type are octet strings of size 3 (that is, 24
bits) that contain a Flow Label value in the rightmost 20 bits padded
on the left with b’0000’.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.47
NAME ’pcelsIPHdrFlowLabel’
DESC ’IP flow label’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
5.22. The Structural Class pcels8021Filter
The pcels8021Filter class provides 802.1 attributes for performing
filtering on 802.1 headers. It is mapped from the 8021Filter class
[PCIM_EXT]. The pcels8021Filter class is a structural object class
and it is derived from the pcelsFilterEntryBase class.
The pcels8021Filter class is defined as follows:
( 1.3.6.1.1.9.1.54
NAME ’pcels8021Filter’
DESC ’802.1 header filter’
SUP pcelsFilterEntryBase
STRUCTURAL
MAY ( pcels8021HdrSourceMACAddress
$ pcels8021HdrSourceMACMask
$ pcels8021HdrDestMACAddress
$ pcels8021HdrDestMACMask
$ pcels8021HdrProtocolID
$ pcels8021HdrPriority
$ pcels8021HdrVLANID )
)
Applications MUST assume ’all values’ for optional (MAY) attributes
not present in a pcels8021Filter entry.
[PCIM_EXT] defines several constraints for the 8021Filter class and
its properties. All these constraints (even those that, for brevity,
are not reiterated in this document) apply to the pcels8021Filter
class and its attributes. A pcels8021Filter entry that violates any
of these constraints SHOULD be treated as invalid and the policy
rules or groups associated to this entry SHOULD be treated as being
disabled, meaning that the execution of such policy rules or groups
SHOULD be stopped.
The pcels8021HdrSourceMACAddress attribute type represents a source
MAC address. It is mapped from the 8021Filter.8021HdrSrcMACAddr
property [PCIM_EXT]. This attribute type is of syntax OctetString
[LDAP_SYNTAX]. It has an equality matching rule of octetStringMatch
[LDAP_SCHEMA] and an ordering matching rule of
octetStringOrderingMatch [LDAP_MATCH]. Attributes of this type can
only have a single value. The only allowed values for attributes of
this type are octet strings with a size of 6.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.48
NAME ’pcels8021HdrSourceMACAddress’
DESC ’Source MAC address’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcels8021HdrSourceMACMask attribute type represents the a mask to
be used in comparing the source MAC address. It is mapped from the
8021Filter.8021HdrSrcMACMask property [PCIM_EXT]. This attribute
type is of syntax OctetString [LDAP_SYNTAX]. It has an equality
matching rule of octetStringMatch [LDAP_SCHEMA] and an ordering
matching rule of octetStringOrderingMatch [LDAP_MATCH]. Attributes
of this type can only have a single value. The only allowed values
for attributes of this type are octet strings with a size of 6.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.49
NAME ’pcels8021HdrSourceMACMask’
DESC ’Source MAC address mask’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcels8021HdrDestMACAddress attribute type represents a
destination MAC address. It is mapped from the
8021Filter.8021HdrDestMACAddr property [PCIM_EXT]. This attribute
type is of syntax OctetString [LDAP_SYNTAX]. It has an equality
matching rule of octetStringMatch [LDAP_SCHEMA] and an ordering
matching rule of octetStringOrderingMatch [LDAP_MATCH]. Attributes
of this type can only have a single value. The only allowed values
for attributes of this type are octet strings with a size of 6.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.50
NAME ’pcels8021HdrDestMACAddress’
DESC ’Destination MAC address’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcels8021HdrDestMACMask attribute type represents the a mask to
be used in comparing the destination MAC address. It is mapped from
the 8021Filter.8021HdrDestMACMask property [PCIM_EXT]. This
attribute type is of syntax OctetString [LDAP_SYNTAX]. It has an
equality matching rule of octetStringMatch [LDAP_SCHEMA] and an
ordering matching rule of octetStringOrderingMatch [LDAP_MATCH].
Attributes of this type can only have a single value. The only
allowed values for attributes of this type are octet strings with a
size of 6.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.51
NAME ’pcels8021HdrDestMACMask’
DESC ’Destination MAC address mask’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
SINGLE-VALUE
)
The pcels8021HdrProtocolID attribute type indicates an Ethernet
protocol type. It is mapped from the 8021Filter.8021HdrProtocolID
property [PCIM_EXT]. This attribute type is of syntax Integer
[LDAP_SYNTAX]. It has an equality matching rule of integerMatch
[LDAP_SYNTAX] and an ordering matching rule of integerOrderingMatch
[LDAP_MATCH]. Attributes of this type can have multiple values. No
order is implied. The only allowed values for attributes of this
type are integers in the range 0..65535 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.52
NAME ’pcels8021HdrProtocolID’
DESC ’Ethernet protocol ID’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
)
The pcels8021HdrPriority attribute type indicates an 802.1Q priority.
It is mapped from the 8021Filter.8021HdrPriorityValue property
[PCIM_EXT]. This attribute type is of syntax Integer [LDAP_SYNTAX].
It has an equality matching rule of integerMatch [LDAP_SYNTAX] and an
ordering matching rule of integerOrderingMatch [LDAP_MATCH].
Attributes of this type can have multiple values. No order is
implied. The only allowed values for attributes of this type are
integers in the range 0..7 (inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.53
NAME ’pcels8021HdrPriority’
DESC ’802.1Q priority’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
)
The pcels8021HdrVLANID attribute type indicates an 802.1Q VLAN
Identifier. It is mapped from the 8021Filter.8021HdrVLANID property
[PCIM_EXT]. This attribute type is of syntax Integer [LDAP_SYNTAX].
It has an equality matching rule of integerMatch [LDAP_SYNTAX] and an
ordering matching rule of integerOrderingMatch [LDAP_MATCH].
Attributes of this type can have multiple values. The only allowed
values for attributes of this type are integers in the range 0..4095
(inclusive).
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.54
NAME ’pcels8021HdrVLANID’
DESC ’802.1Q VLAN ID’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
)
5.23. The Auxiliary Class pcelsFilterListAuxClass
The pcelsFilterListAuxClass class represents a collection of device-
level filters aggregated in a policy condition. It is mapped from
the FilterList class [PCIM_EXT]. pcelsFilterListAuxClass instances
can be used as conditions in policy rules or as components in
compound conditions. The pcelsFilterListAuxClass class is an
auxiliary object class and it is derived from the
pcimConditionAuxClass class [PCLS].
The pcelsFilterListAuxClass class is defined as follows:
( 1.3.6.1.1.9.1.55
NAME ’pcelsFilterListAuxClass’
DESC ’Collection of pcelsFilterEntryBase filters’
SUP pcimConditionAuxClass
AUXILIARY
MAY ( pcelsFilterListName
$ pcelsFilterDirection
$ pcelsFilterEntryList )
)
The pcelsFilterListName attribute type may be used as naming
attribute for pcelsFilterListAuxClass entries. This attribute type
is of syntax Directory String [LDAP_SYNTAX]. It has an equality
matching rule of caseIgnoreMatch, an ordering matching rule of
caseIgnoreOrderingMatch and a substrings matching rule of
caseIgnoreSubstringsMatch [LDAP_SYNTAX]. Attributes of this type can
only have a single value.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.55
NAME ’pcelsFilterListName’
DESC ’User-friendly name of a FilterList’
EQUALITY caseIgnoreMatch
ORDERING caseIgnoreOrderingMatch
SUBSTR caseIgnoreSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15
SINGLE-VALUE
)
The pcelsFilterDirection attribute type indicates the direction of
the packets or messages relative to the interface where the filter is
applied. It is mapped from the FilterList.Direction property
[PCIM_EXT]. This attribute type is of syntax Integer [LDAP_SYNTAX].
It has an equality matching rule of integerMatch [LDAP_SYNTAX] and an
ordering matching rule of integerOrderingMatch [LDAP_MATCH].
Attributes of this type can only have a single value. The only
allowed values for attributes of this type are 0 (NotApplicable), 1
(Input), 2 (Output), 3 (Both) and 4 (Mirrored). If this attribute is
missing from a pcelsFilterListAuxClass instance, applications MUST
assume that a direction is not applicable.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.56
NAME ’pcelsFilterDirection’
DESC ’Direction to which this filter is applied’
EQUALITY integerMatch
ORDERING integerOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27
SINGLE-VALUE
)
The pcelsFilterEntryList attribute type realizes the
EntriesInFilterList association [PCIM_EXT]. This attribute type is
of syntax DN [LDAP_SYNTAX]. It has an equality matching rule of
distinguishedNameMatch [LDAP_SYNTAX]. Attributes of this type can
have multiple values. The only allowed values for
pcelsFilterEntryList attributes are DNs of pcelsFilterEntryBase
entries. In a pcelsFilterListAuxClass, the pcelsFilterEntryList
attribute represents the associations between this filter collection
and its components.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.57
NAME ’pcelsFilterEntryList’
DESC ’Unordered set of DNs of pcelsFilterEntryBase entries’
EQUALITY distinguishedNameMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12
)
The EntrySequence property of the association EntriesInFilterList is
restricted to a single value (’0’) [PCIM_EXT] which makes it
redundant. Therefore, its mapping to an LDAP schema element is
unnecessary.
5.24. The Auxiliary Class pcelsVendorVariableAuxClass
The pcelsVendorVariableAuxClass class provides a general extension
mechanism for representing policy variables that have not been
specifically modeled. Instead, its two properties are used to define
the content and format of the variable, as explained below. This
class is intended for vendor-specific extensions that are not
amenable to using pcelsVariable; standardized extensions SHOULD NOT
use this class.
The pcelsVendorVariableAuxClass class is an auxiliary object class
and it is derived from the pcelsVariable class.
The pcelsVendorVariableAuxClass class is defined as follows:
( 1.3.6.1.1.9.1.56
NAME ’pcelsVendorVariableAuxClass’
DESC ’Defines registered means to describe a policy variable’
SUP pcelsVariable
AUXILIARY
MAY ( pcelsVendorVariableData $
pcelsVendorVariableEncoding )
)
The pcelsVendorVariableData attribute provides a general mechanism
for representing policy variables that have not been specifically
modeled. This attribute type is of syntax OctetString [LDAP_SYNTAX].
It has an equality matching rule of octetStringMatch [LDAP_SCHEMA]
and an ordering matching rule of octetStringOrderingMatch
[LDAP_MATCH]. Attributes of this type can have multiple values. In
pcelsVendorVariableAuxClass instances, the format of the values for
attributes of this type is identified by the OID stored in the
pcelsVendorVariableEncoding attribute.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.58
NAME ’pcelsVendorVariableData’
DESC ’Mechanism for representing variables that have not
been specifically modeled’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
)
The pcelsVendorVariableEncoding attribute identifies the format for
representing policy variables that have not been specifically
modeled. This attribute type is of syntax OID [LDAP_SYNTAX]. It has
an equality matching rule of objectIdentifierMatch [LDAP_SYNTAX].
Attributes of this type can only have a single value. In
pcelsVendorVariableAuxClass instances, the
pcelsVendorVariableEncoding attribute is used to identify the format
and semantics for the pcelsVendorVariableData attribute values.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.59
NAME ’pcelsVendorVariableEncoding’
DESC ’Identifies the format and semantics for policy variables’
EQUALITY objectIdentifierMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.38
SINGLE-VALUE
)
5.25. The Auxiliary Class pcelsVendorValueAuxClass
The pcelsVendorValueAuxClass class provides a general extension
mechanism for representing policy values that have not been
specifically modeled. Instead, its two properties are used to define
the content and format of the policy value, as explained below. This
class is intended for vendor-specific extensions that are not
amenable to using pcelsValueAuxClass; standardized extensions SHOULD
NOT use this class.
The pcelsVendorValueAuxClass class is an auxiliary object class and
it is derived from the pcelsValueAuxClass class.
The pcelsVendorValueAuxClass class is defined as follows:
( 1.3.6.1.1.9.1.57
NAME ’pcelsVendorValueAuxClass’
DESC ’Defines registered means to describe a policy value’
SUP pcelsValueAuxClass
AUXILIARY
MAY ( pcelsVendorValueData $
pcelsVendorValueEncoding )
)
The pcelsVendorValueData attribute provides a general mechanism for
representing policy values that have not been specifically modeled.
This attribute type is of syntax OctetString [LDAP_SYNTAX]. It has
an equality matching rule of octetStringMatch [LDAP_SCHEMA] and an
ordering matching rule of octetStringOrderingMatch [LDAP_MATCH].
Attributes of this type can have multiple values. In
pcelsVendorValueAuxClass instances, the format of the values for
attributes of this type is identified by the OID stored in the
pcelsVendorValueEncoding attribute.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.60
NAME ’pcelsVendorValueData’
DESC ’Mechanism for representing values that have not been
specifically modeled’
EQUALITY octetStringMatch
ORDERING octetStringOrderingMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.40
)
The pcelsVendorValueEncoding attribute identifies the format for
representing policy values that have not been specifically modeled.
This attribute type is of syntax OID [LDAP_SYNTAX]. It has an
equality matching rule of objectIdentifierMatch [LDAP_SYNTAX].
Attributes of this type can only have a single value. In
pcelsVendorVarlueAuxClass instances, the pcelsVendorValueEncoding
attribute is used to identify the format and semantics for the
pcelsVendorValueData attribute values.
This attribute type is defined as follows:
( 1.3.6.1.1.9.2.61
NAME ’pcelsVendorValueEncoding’
DESC ’Identifies the format and semantics for policy values’
EQUALITY objectIdentifierMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.38
SINGLE-VALUE
)
6. Security Considerations
The Policy Core LDAP Schema [PCLS] describes the general security
considerations related to the general core policy schema. The
extensions defined in this document do not introduce any additional
considerations related to security.
7. IANA Considerations
Refer to RFC 3383, "Internet Assigned Numbers Authority (IANA)
Considerations for the Lightweight Directory Access Protocol (LDAP)"
[LDAP-IANA].
7.1. Object Identifiers
The IANA has registered an LDAP Object Identifier for use in this
technical specification according to the following template:
Subject: Request for LDAP OID Registration
Person & e-mail address to contact for further information:
Mircea Pana (mpana@metasolv.com)
Specification: RFC 4104
Author/Change Controller: IESG
Comments:
The assigned OID is used as a base for identifying
a number of schema elements defined in this document.
IANA has assigned an OID of 1.3.6.1.1.9 with the name of pcelsSchema
to this registration as recorded in the following registry:
http://www.iana.org/assignments/smi-numbers
7.2. Object Identifier Descriptors
The IANA has registered the LDAP Descriptors used in this technical
specification as detailed in the following template:
Subject: Request for LDAP Descriptor Registration Update
Descriptor (short name): see comment
Object Identifier: see comment
Person & e-mail address to contact for further information:
Mircea Pana (mpana@metasolv.com)
Usage: see comment
Specification: RFC 4104
Author/Change Controller: IESG
Comments:
The following descriptors have been added:
NAME Type OID
-------------- ---- ------------
pcelsPolicySet O 1.3.6.1.1.9.1.1
pcelsPolicySetAssociation O 1.3.6.1.1.9.1.2
pcelsGroup O 1.3.6.1.1.9.1.3