Changes between Version 2 and Version 3 of Creddy
- Timestamp:
- Oct 1, 2010 2:13:21 PM (14 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Creddy
v2 v3 81 81 generate an X.509 attribute cert representing an ABAC credential 82 82 <P> 83 An attribute cert has one or more subjects. A single subject may be defined without a role. Otherwise, subjects are defined by a pair of a --subject-{cert,id} and --subject-role. Providing multiple subjects creates an intersection certificate. 84 <P> 83 85 <DL COMPACT> 84 86 <DT><B>--issuer</B> … … 95 97 96 98 <DD> 97 role in issuer's local attribute space . Must start with a letter and be alphanumeric thereafter.99 role in issuer's local attribute space 98 100 <P> 99 101 <DT><B>--subject-cert</B> 100 102 101 103 <DD> 102 X.509 identity cert representing the principal to which the role is being issued. This is mutually exclusive to --subject-id.104 X.509 identity cert representing the principal to which the role is being issued. This fulfills the same purpose as --subject-id and should only be used once per subject. 103 105 <P> 104 106 <DT><B>--subject-id</B> 105 107 106 108 <DD> 107 public key identifier (SHA1 hash) of the principal to which the role is being issued. This is mutually exclusive to --subject-cert.109 public key identifier (SHA1 hash) of the principal to which the role is being issued. This fulfills the same purpose as --subject-cert and should only be used once per subject. 108 110 <P> 109 111 <DT><B>--subject-role</B> 110 112 111 113 <DD> 112 optional role in subject's local attribute space. Must start with a letter and be alphanumeric thereafter.If the issuer is A, role is r1, subject is B, and subject-role is r2, the attribute issued will be A.r1 <- B.r2.114 optional role in subject's local attribute space. If the issuer is A, role is r1, subject is B, and subject-role is r2, the attribute issued will be A.r1 <- B.r2. 113 115 <P> 114 116 <DT><B>--validity</B> … … 121 123 <DD> 122 124 where to save DER-encoded attribute cert. In order to interoperate with the rest of ABAC, this name should end in _attr.der. 125 <P> 123 126 <P> 124 127 </DL>