99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<?xml version='1.0' encoding='UTF-8' ?>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!--
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec Copyright (c) 2006, 2010, Oracle and/or its affiliates. All rights reserved.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys CDDL HEADER START
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys The contents of this file are subject to the terms of the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Common Development and Distribution License (the "License").
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys You may not use this file except in compliance with the License.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys or http://www.opensolaris.org/os/licensing.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys See the License for the specific language governing permissions
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys and limitations under the License.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys When distributing Covered Code, include this CDDL HEADER in each
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys file and include the License file at usr/src/OPENSOLARIS.LICENSE.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If applicable, add the following below this CDDL HEADER, with the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys fields enclosed by brackets "[]" replaced with your own identifying
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys information: Portions Copyright [yyyy] [name of copyright owner]
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys CDDL HEADER END
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys-->
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!--Element Definitions-->
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT kmf-policy-db (kmf-policy*)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy-db allow-local-files (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ELEMENT kmf-policy (validation-methods, key-usage-set?, ext-key-usage?, cert-to-name-mapping?)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy name CDATA #REQUIRED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy ignore-date (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy ignore-unknown-eku (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy ignore-trust-anchor (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy validity-adjusttime CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy ta-name CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST kmf-policy ta-serial CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT validation-methods (ocsp?, crl?)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT ocsp (ocsp-basic, responder-cert?)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT ocsp-basic EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST ocsp-basic
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys responder CDATA #IMPLIED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys proxy CDATA #IMPLIED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys uri-from-cert (TRUE|FALSE) #IMPLIED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys response-lifetime CDATA #IMPLIED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys ignore-response-sign (TRUE|FALSE) #IMPLIED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT responder-cert EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST responder-cert
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys name CDATA #REQUIRED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys serial CDATA #REQUIRED
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT crl EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl basefilename CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl directory CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl get-crl-uri (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl proxy CDATA #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl ignore-crl-sign (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST crl ignore-crl-date (TRUE|FALSE) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT key-usage-set (key-usage+)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT key-usage EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST key-usage use (digitalSignature | nonRepudiation |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys keyEncipherment | dataEncipherment | keyAgreement |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys keyCertSign | cRLSign | encipherOnly | decipherOnly) #IMPLIED>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT ext-key-usage (eku-name*, eku-oid*)>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT eku-name EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST eku-name name (serverAuth | clientAuth |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys codeSigning | emailProtection |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys ipsecEndSystem | ipsecTunnel | ipsecUser |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys timeStamping | OCSPSigning) #IMPLIED >
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ELEMENT eku-oid EMPTY>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!ATTLIST eku-oid oid CDATA #IMPLIED>
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ELEMENT cert-to-name-mapping ANY>
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ATTLIST cert-to-name-mapping mapper-name CDATA #IMPLIED>
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ATTLIST cert-to-name-mapping mapper-directory CDATA #IMPLIED>
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ATTLIST cert-to-name-mapping mapper-pathname CDATA #IMPLIED>
269e59f9a28bf47e0f463e64fc5af4a408b73b21Jan Pechanec<!ATTLIST cert-to-name-mapping mapper-options CDATA #IMPLIED>