RE: Cannot search usercertificate binary data with raw data

Luis Neves <[email protected]> Sat, 8 May 2010 18:07:38 +0000
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
--_4eca2c73-9d07-471d-95bc-d0c358a39d1a_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable


So how to do a ldapsearch against usercertificate using hexadecimal codes a=
s filter ? Is not possible at all?

Luis

> Date: Sat=2C 8 May 2010 07:54:40 -0700
> From: [email protected]
> To: [email protected]
> Subject: Re: Cannot search usercertificate binary data with raw data
> CC: [email protected]
>=20
> Michael Str=F6der wrote:
> > Howard Chu wrote:
> >> Michael Str=F6der wrote:
> >>> But userCertificate has certificateExactMatch (2.5.13.34) defined as
> >>> equality matching rule. This is *not* the octetStringMatch (2.5.13.17=
)
> >>> matching rule.
> >>
> >> It is legal to use an octet string for certificateExactMatch. In
> >> OpenLDAP the octet string is simply parsed and turned into a certifica=
te
> >> assertion value and then matched as usual.
> >
> > It does not work for me with 2.4.22.
> > It's a cert which was downloaded from the directory.
>=20
> My mistake. See RFC4523. The filter must use a matching assertion value=
=2C it=20
> cannot use the actual certificate.
>=20
> --=20
>    -- Howard Chu
>    CTO=2C Symas Corp.           http://www.symas.com
>    Director=2C Highland Sun     http://highlandsun.com/hyc/
>    Chief Architect=2C OpenLDAP  http://www.openldap.org/project/
 		 	   		 =20
_________________________________________________________________
Hotmail: Trusted email with Microsoft=92s powerful SPAM protection.
https://signup.live.com/signup.aspx?id=3D60969=

--_4eca2c73-9d07-471d-95bc-d0c358a39d1a_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<style><!--
.hmmessage P
{
margin:0px=3B
padding:0px
}
body.hmmessage
{
font-size: 10pt=3B
font-family:Verdana
}
--></style>
</head>
<body class=3D'hmmessage'>
So how to do a ldapsearch against usercertificate using hexadecimal codes a=
s filter ? Is not possible at all?<br><br>Luis<br><br>&gt=3B Date: Sat=2C 8=
 May 2010 07:54:40 -0700<br>&gt=3B From: [email protected]<br>&gt=3B To: michae=
[email protected]<br>&gt=3B Subject: Re: Cannot search usercertificate binary =
data with raw data<br>&gt=3B CC: [email protected]<br>&gt=3B <=
br>&gt=3B Michael Str=F6der wrote:<br>&gt=3B &gt=3B Howard Chu wrote:<br>&g=
t=3B &gt=3B&gt=3B Michael Str=F6der wrote:<br>&gt=3B &gt=3B&gt=3B&gt=3B But=
 userCertificate has certificateExactMatch (2.5.13.34) defined as<br>&gt=3B=
 &gt=3B&gt=3B&gt=3B equality matching rule. This is *not* the octetStringMa=
tch (2.5.13.17)<br>&gt=3B &gt=3B&gt=3B&gt=3B matching rule.<br>&gt=3B &gt=
=3B&gt=3B<br>&gt=3B &gt=3B&gt=3B It is legal to use an octet string for cer=
tificateExactMatch. In<br>&gt=3B &gt=3B&gt=3B OpenLDAP the octet string is =
simply parsed and turned into a certificate<br>&gt=3B &gt=3B&gt=3B assertio=
n value and then matched as usual.<br>&gt=3B &gt=3B<br>&gt=3B &gt=3B It doe=
s not work for me with 2.4.22.<br>&gt=3B &gt=3B It's a cert which was downl=
oaded from the directory.<br>&gt=3B <br>&gt=3B My mistake. See RFC4523. The=
 filter must use a matching assertion value=2C it <br>&gt=3B cannot use the=
 actual certificate.<br>&gt=3B <br>&gt=3B -- <br>&gt=3B    -- Howard Chu<br=
>&gt=3B    CTO=2C Symas Corp.           http://www.symas.com<br>&gt=3B    D=
irector=2C Highland Sun     http://highlandsun.com/hyc/<br>&gt=3B    Chief =
Architect=2C OpenLDAP  http://www.openldap.org/project/<br> 		 	   		  <br =
/><hr />Hotmail: Trusted email with Microsoft=92s powerful SPAM protection.=
 <a href=3D'https://signup.live.com/signup.aspx?id=3D60969' target=3D'_new'=
>Sign up now.</a></body>
</html>=

--_4eca2c73-9d07-471d-95bc-d0c358a39d1a_--