[an error occurred while processing this directive]

HP OpenVMS Systems

X.500
» 

HP OpenVMS Systems

OpenVMS information

» What's new on our site
» Upcoming events
» Configuration and buying assistance
» Send us your comments

HP OpenVMS systems

» OpenVMS software
» Supported Servers
» OpenVMS virtualization
» OpenVMS solutions and partners
» OpenVMS success stories
» OpenVMS service and support
» OpenVMS resources and information
» OpenVMS documentation
» Education and training

Directory Service

» Discuss this Product
» Sign up for Directory and Messaging Newsletter
» Directory and Messaging page

Evolving business value

» Business Systems Evolution
» AlphaServer systems transition planning
» Alpha RetainTrust program

Related links

» HP Integrity servers
» HP Alpha systems
» HP storage
» HP software
» HP products and services
» HP solutions
» HP support
disaster proof
HP Integrity server animation
HP Integrity server animation
Content starts here

X.500 directory service v4.0 security

The Compaq X.500 Directory Service supports a subset of the Simplified Access Control scheme from the 1993 edition of the standard. This allows administrators to define policies that control access rights (such as read, browse, modify, remove) to entries and individual attributes within a particular part of the directory (naming context).

The Compaq X.500 Directory Service allows for the authentication of users by name and password. It also allows access to be restricted based on network address and for chained operations. X.500 V4.0 on Tru64 UNIX has been certified with the Entrust V5.0 security product.

Authentication

A user is authenticated by a distinguished name and password.

Access control

Certain objects in the directory can have a prescriptive ACI (Access Control Information) attribute. Any subordinate object is protected by whatever prescriptive ACI protects the relevant branch of the Directory Information Tree. A prescriptive ACI, together with the distinguished name of an authenticated user, can grant these kinds of access:

  • Read
  • Compare
  • Browse
  • Add
  • Modify
  • Remove
  • Filter Match
  • Rename
  • Return DN
  • Disclose on Error

Trust relationships

You can use NCL to set up a trust relationship between two DSAs.


» back to X.500 directory service page