openldap/servers/slapd/schema/pilot.schema

364 lines
14 KiB
Plaintext
Raw Normal View History

1999-09-09 06:52:19 +08:00
# $OpenLDAP$
1999-04-27 14:34:10 +08:00
# These come from RFC1274 and are in ASN.1 syntax. They have been
# translated with some imagination. Only attributes and classes we
# already had are here. In general, the matching rules in the
# attribute types are incomplete or incorrect and have to be checked.
# Note: It seems that the pilot schema evolved beyond what was
# described in RFC1274. It also seems that Umich followed the changes
# but we don't know where are documented. More worrisome is that it
# seems that Netscape does not know either. Searches on Altavista
# have not shed any light, so we will have to ask for help.
1999-10-06 08:10:08 +08:00
# This file uses definitions from core.schema
1999-04-27 14:34:10 +08:00
# ccitt.data.pss.ucl.pilot ( 0.9.2342.19200300.100 )
# 1 pilotAttributeType
# 3 pilotAttributeSyntax
# 4 pilotObjectClass
# 10 pilotGroups
# Believe it or not, this is case-insensitive
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.2 NAME 'textEncodedORAddress'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.3 NAME ( 'mail' 'rfc822Mailbox' )
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreIA5Match
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.4 NAME 'info' EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.5 NAME ( 'drink' 'favouriteDrink' )
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.6 NAME 'roomNumber'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.7 NAME 'photo'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.8 NAME 'userClass'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.9 NAME 'host'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.10 NAME 'manager'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.11 NAME 'documentIdentifier'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.12 NAME 'documentTitle'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.13 NAME 'documentVersion'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.14 NAME 'documentAuthor'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.15 NAME 'documentLocation'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.20 NAME ( 'homeTelephoneNumber' 'homePhone' )
1999-04-27 14:34:10 +08:00
EQUALITY telephoneNumberMatch
SUBSTR telephoneNumberSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.21 NAME 'secretary'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
# Netscape defines this with syntax 1.15 TBC
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.22 NAME 'otherMailbox'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.39 )
1999-04-27 14:34:10 +08:00
# Netscape defines this with syntax 1.15 TBC
# Mathcing rules for this are unknown
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.23 NAME 'lastModifiedTime'
1999-04-27 14:34:10 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.53 )
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.24 NAME 'lastModifiedBy'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
# This is the definition as defined in RFC2247
# Terrific, we don't know about caseIgnoreIA5SubstringsMatch
1999-04-27 14:34:10 +08:00
# See RFC2247 define in core.schema
#attributetype ( 0.9.2342.19200300.100.1.25 NAME 'dc'
# EQUALITY caseIgnoreIA5Match
# SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE )
1999-04-27 14:34:10 +08:00
# This is aRecord in RFC1274. However, objectclass dNSDomain as we
# and Netscape use it is very different.
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.26 NAME 'dNSRecord'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
# 0.9.2342.19200300.100.1.27 was probably intended to be mDRecord in
# RFC1274, but they got it wrong and did not define it, thought it
# is referenced by dNSDomain in it.
# 0.9.2342.19200300.100.1.28 was mXRecord in RFC1274
# 0.9.2342.19200300.100.1.29 was nSRecord in RFC1274
# 0.9.2342.19200300.100.1.30 was sOARecord in RFC1274
# 0.9.2342.19200300.100.1.31 was cNAMERecord in RFC1274
# Terrific, we don't know about caseIgnoreIA5SubstringsMatch
#attribute ( 0.9.2342.19200300.100.1.37 NAME 'associatedDomain'
# EQUALITY caseIgnoreIA5Match
# SUBSTR caseIgnoreIA5SubstringsMatch
# SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.37 NAME 'associatedDomain'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreIA5Match
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.38 NAME 'associatedName'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
# Netscape gives syntax 1.15 to this. TBC
# We take the matching rules from postalAddress in RFC2256
# Show stopper: we don't have the definition of caseIgnoreListSubstringsMatch
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.39 NAME 'homePostalAddress'
EQUALITY caseIgnoreListMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.41 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.40 NAME 'personalTitle'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.41 NAME ( 'mobileTelephoneNumber' 'mobile' )
1999-04-27 14:34:10 +08:00
EQUALITY telephoneNumberMatch
SUBSTR telephoneNumberSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.42 NAME ( 'pagerTelephoneNumber' 'pager' )
1999-04-27 14:34:10 +08:00
EQUALITY telephoneNumberMatch
SUBSTR telephoneNumberSubstringsMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.50 )
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.43 NAME ( 'co' 'friendlyCountryName' )
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.44 NAME 'uniqueIdentifier'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.45 NAME 'organizationalStatus'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.46 NAME 'janetMailbox'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreIA5Match
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
# Netscape gives syntax 1.27 (integer). However, 1.32 is only listed
# in RFC2252 without explanation. The SINGLE-VALUE thing comes from
# Netscape and is not backed by RFC1274.
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.47 NAME 'mailPreferenceOption'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.32 SINGLE-VALUE )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.48 NAME 'buildingName'
EQUALITY caseIgnoreMatch
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE )
1999-04-27 14:34:10 +08:00
# 0.9.2342.19200300.100.1.49 was dSAQuality in RFC1274
# 0.9.2342.19200300.100.1.50 was singleLevelQuality in RFC1274
# 0.9.2342.19200300.100.1.51 was subtreeMinimumQuality in RFC1274
# 0.9.2342.19200300.100.1.52 was subtreeMaximumQuality in RFC1274
# Netscape assigns binary syntax to this. RFC1274 is more detailed
# about this but RFC2252 does not seem to list a specific syntax.
# We had this as 'bin'
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.53 NAME 'personalSignature'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.54 NAME 'dITRedirect'
1999-04-27 14:34:10 +08:00
EQUALITY distinguishedNameMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
# Netscape gives syntax 1.5 to this. We had it as 'bin'.
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.55 NAME 'audio'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.4 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.56 NAME 'documentPublisher'
1999-04-27 14:34:10 +08:00
EQUALITY caseIgnoreMatch
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
# From RFC 2798 (inetOrgPerson)
1999-10-14 05:57:44 +08:00
attributetype ( 0.9.2342.19200300.100.1.60
NAME 'jpegPhoto'
DESC 'a JPEG image'
SYNTAX 1.3.6.1.4.1.1466.115.121.1.28 )
1999-04-27 14:34:10 +08:00
# These attributes are pilot-related attributes that we had and Netscape
# has too, however, the OID is unknown for them and Netscape uses a
# string in place of the missing OID. We will do the same until we
# can make head or tails of this.
1999-10-14 05:57:44 +08:00
attributetype ( abstract-oid NAME 'abstract'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( authorcn-oid NAME ( 'documentAuthorCommonName' 'authorCn' )
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( authorsn-oid NAME ( 'documentAuthorSurname' 'authorSn' )
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( documentStore-oid NAME 'documentStore'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( keyWords-oid NAME 'keyWords'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( obsoletedByDocument-oid NAME 'obsoletedByDocument'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( obsoletesDocument-oid NAME 'obsoletesDocument'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( subject-oid NAME 'subject'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( updatedByDocument-oid NAME 'updatedByDocument'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
1999-10-14 05:57:44 +08:00
attributetype ( updatesDocument-oid NAME 'updatesDocument'
1999-06-09 01:41:09 +08:00
SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )
1999-04-27 14:34:10 +08:00
# In classes, STRUCTURAL or AUXILIARY is chosen depending on the
# textual description that accompanies the class in RFC1274
# This is pilotObject from the RFC. However, we had both photo
# and jpegPhoto attributes. Nestcape does too.
objectclass ( 0.9.2342.19200300.100.4.3 NAME 'pilotObject' SUP top
AUXILIARY MAY ( info $ photo $ manager $ uniqueIdentifier $
lastModifiedTime $ lastModifiedBy $ dITRedirect $ audio $
jpegPhoto ) )
# This is probably wrong. RFC1274 defines a pilotPerson. We did not
# have it and we did have a newPilotPerson instead. However, the
# definition is the same. Maybe it changed and was not reflected
# in the RFC.
objectclass ( 0.9.2342.19200300.100.4.4 NAME 'newPilotPerson' SUP person
STRUCTURAL MAY ( uid $ textEncodedORAddress $ mail $ drink $
roomNumber $ userClass $ homePhone $ homePostalAddress $
secretary $ personalTitle $ preferredDeliveryMethod $
businessCategory $ janetMailbox $ otherMailbox $ mobile $
pager $ organizationalStatus $ mailPreferenceOption $
personalSignature ) )
# The text is unclear about whether it is STRUCTURAL or AUXILIARY
# I think it was meant to be STRUCTURAL, it is the least restrictive
# of the options and RFC2377 explains uidObject as an auxiliary.
objectclass ( 0.9.2342.19200300.100.4.5 NAME 'account' SUP top
STRUCTURAL MUST uid MAY ( description $ seeAlso $ l $ o $ ou $
host ) )
# Netscape says this is derived from pilotObject, but RFC1274 says top.
# Which is it? Our attribute list matches that of Netscape, so we will
# go with Netscape for the time being.
# Besides, this objectclass is a mess. I can only presume that
# originally documentAuthor, but later someone noticed that not all
# authors had DN's, so authorCN and authorSN were added. Other
# attributes were added as well. However, either no one remembered to
# assign OIDs to these attribute types or their assignments have been
# lost. See their definitions above for the Netscape kludge that we
# have adopted. FIX NEEDED.
objectclass ( 0.9.2342.19200300.100.4.6 NAME 'document' SUP pilotObject
MUST documentIdentifier MAY ( cn $ description $ seeAlso $ l $
o $ ou $ documentTitle $ documentVersion $ documentAuthor $
documentLocation $ documentPublisher $
abstract $ authorCN $ authorSN $ documentStore $ keywords $
obsoletedByDocument $ obsoletesDocument $ subject $
updatedByDocument $ updatesDocument ) )
objectclass ( 0.9.2342.19200300.100.4.7 NAME 'room' SUP top STRUCTURAL
MUST cn MAY ( roomNumber $ description $ seeAlso $ telephoneNumber ) )
objectclass ( 0.9.2342.19200300.100.4.9 NAME 'documentSeries' SUP top
STRUCTURAL MUST cn MAY ( description $ seeAlso $ telephonenumber $
l $ o $ ou ) )
# This definition is much longer than that in RFC1274 and is taken from RFC2247
objectclass ( 0.9.2342.19200300.100.4.13 NAME 'domain' SUP top STRUCTURAL
MUST dc
MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $
x121Address $ registeredAddress $ destinationIndicator $
preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $
telephoneNumber $ internationaliSDNNumber $ facsimileTelephoneNumber $
street $ postOfficeBox $ postalCode $ postalAddress $
physicalDeliveryOfficeName $ st $ l $ description $ o $
associatedName ) )
# This class has in RFC1274 two attributes postalAttributeSet and
# telecomunicationAttributeSet that we did not have. We let them out
# for now. Netscape does not have them either.
objectclass ( 0.9.2342.19200300.100.4.14 NAME 'RFC822localPart' SUP domain
MAY ( cn $ sn $ description $ seeAlso $ telephonenumber ) )
# Another wonderful inconsistency. This objectclass has little
# relationship to the way it was defined in RFC1274, that was derived
# from domain, adding ARecord, MDRecord, MXRecord, NSRecord, SOARecord
# and CNAMERecord attribute types of syntax DNSRecordSyntax. On the
# other hand, we had dNSRecord and Netscape has it too. The OID for
# dNSRecord is the one used in RFC1274 for ARecord. Netscape also has
# a manager attribute type here that we did not. It seems a mistake
# and we do not include it.
objectclass ( 0.9.2342.19200300.100.4.15 NAME 'dNSDomain' SUP 'domain'
MAY dnsrecord )
objectclass ( 0.9.2342.19200300.100.4.17 NAME 'domainRelatedObject'
SUP 'top' MUST associatedDomain )
# Well, first notice we (and Netscape) were using co as short for
# friendlyCountryName
objectclass ( 0.9.2342.19200300.100.4.18 NAME 'friendlyCountry' SUP country
MUST co )
objectclass ( 0.9.2342.19200300.100.4.19 NAME 'simpleSecurityObject'
SUP top MUST userPassword )
# Nice test case of class with two superiors. Netscape does not give
# OID for this objectclass and gives top as its superior. We use the
# OID given in RFC1274
objectclass ( 0.9.2342.19200300.100.4.20 NAME 'pilotOrganization'
SUP ( organization $ organizationalUnit ) MAY buildingName )