C=USEncryption and standards FAQ →

C=US Schemas

These are the schemas behind the C=US agent registry: the OpenLDAP schema for agents, grants, certificate bindings and the maple and tart-cherry use cases; the accountable-delegation extension and its JSON Schema; and the one file every enforcement point reads its scope names from. The files below are the same ones in the project repository, published unchanged.

Files

Full documentation, including the certificate-binding acceptance rule and the JSON-to-LDAP mapping table, is in the repository’s schema README and delegation README.

Read this before writing a consumer

Only a grant authorizes. cequsDeclaredScope on an agent entry is a descriptive label with no time bounds. cequsAuthorizedScope on a cequsAuthorizationGrant, read together with cequsGrantStart and cequsGrantEnd, is the only attribute an evaluator should consult. They were once one attribute, and the unbounded copy bypassed the grant window.

A sponsor claim is not a proofed identity. cequsSponsor records what the registrar asserted. cequsAccountableSponsor is set only after identity proofing, which is not built yet.

LDAP write access is not authorization. Grants, expiry, attestation, revocation and audit are enforced by the service that reads the directory, and it must fail closed.

Loading into a test directory

For a slapd.conf deployment, load the standard schemas first, then the registry, then the delegation extension:

include /etc/ldap/schema/core.schema
include /etc/ldap/schema/cosine.schema
include /etc/ldap/schema/cus-registry.schema
include /etc/ldap/schema/cequs-delegation.schema

Check the configuration with slaptest -f /etc/ldap/slapd.conf -u before starting the server. For a cn=config deployment, convert and load the schemas in a test environment first; don’t hand-edit a live cn=config database.

Limits

The certificate-binding and trusted-issuer classes have been rehearsed on a throwaway OpenLDAP 2.6.10 server but are not applied to the live C=US directory. The delegation extension is for an isolated local test directory only. The maple and tart-cherry records are illustrative and establish no grading standard. An Internet Directory Number under 1.3.6.1.1 has been requested; if one is assigned, the OID root line changes.