1*2139Sjp161948# CCITT was renamed to ITU-T quite some time ago 2*2139Sjp1619480 : ITU-T : itu-t 3*2139Sjp161948!Alias ccitt itu-t 40Sstevel@tonic-gate 50Sstevel@tonic-gate1 : ISO : iso 60Sstevel@tonic-gate 7*2139Sjp1619482 : JOINT-ISO-ITU-T : joint-iso-itu-t 8*2139Sjp161948!Alias joint-iso-ccitt joint-iso-itu-t 90Sstevel@tonic-gate 100Sstevel@tonic-gateiso 2 : member-body : ISO Member Body 110Sstevel@tonic-gate 12*2139Sjp161948iso 3 : identified-organization 13*2139Sjp161948 14*2139Sjp161948identified-organization 132 : certicom-arc 15*2139Sjp161948 16*2139Sjp161948joint-iso-itu-t 23 : international-organizations : International Organizations 17*2139Sjp161948 18*2139Sjp161948international-organizations 43 : wap 19*2139Sjp161948wap 13 : wap-wsg 20*2139Sjp161948 21*2139Sjp161948joint-iso-itu-t 5 1 5 : selected-attribute-types : Selected Attribute Types 220Sstevel@tonic-gate 230Sstevel@tonic-gateselected-attribute-types 55 : clearance 240Sstevel@tonic-gate 250Sstevel@tonic-gatemember-body 840 : ISO-US : ISO US Member Body 260Sstevel@tonic-gateISO-US 10040 : X9-57 : X9.57 270Sstevel@tonic-gateX9-57 4 : X9cm : X9.57 CM ? 280Sstevel@tonic-gate 290Sstevel@tonic-gate!Cname dsa 300Sstevel@tonic-gateX9cm 1 : DSA : dsaEncryption 310Sstevel@tonic-gateX9cm 3 : DSA-SHA1 : dsaWithSHA1 320Sstevel@tonic-gate 330Sstevel@tonic-gate 340Sstevel@tonic-gateISO-US 10045 : ansi-X9-62 : ANSI X9.62 350Sstevel@tonic-gate!module X9-62 360Sstevel@tonic-gate!Alias id-fieldType ansi-X9-62 1 370Sstevel@tonic-gateX9-62_id-fieldType 1 : prime-field 380Sstevel@tonic-gateX9-62_id-fieldType 2 : characteristic-two-field 39*2139Sjp161948X9-62_characteristic-two-field 3 : id-characteristic-two-basis 40*2139Sjp161948X9-62_id-characteristic-two-basis 1 : onBasis 41*2139Sjp161948X9-62_id-characteristic-two-basis 2 : tpBasis 42*2139Sjp161948X9-62_id-characteristic-two-basis 3 : ppBasis 430Sstevel@tonic-gate!Alias id-publicKeyType ansi-X9-62 2 440Sstevel@tonic-gateX9-62_id-publicKeyType 1 : id-ecPublicKey 450Sstevel@tonic-gate!Alias ellipticCurve ansi-X9-62 3 460Sstevel@tonic-gate!Alias c-TwoCurve X9-62_ellipticCurve 0 47*2139Sjp161948X9-62_c-TwoCurve 1 : c2pnb163v1 48*2139Sjp161948X9-62_c-TwoCurve 2 : c2pnb163v2 49*2139Sjp161948X9-62_c-TwoCurve 3 : c2pnb163v3 50*2139Sjp161948X9-62_c-TwoCurve 4 : c2pnb176v1 51*2139Sjp161948X9-62_c-TwoCurve 5 : c2tnb191v1 52*2139Sjp161948X9-62_c-TwoCurve 6 : c2tnb191v2 53*2139Sjp161948X9-62_c-TwoCurve 7 : c2tnb191v3 54*2139Sjp161948X9-62_c-TwoCurve 8 : c2onb191v4 55*2139Sjp161948X9-62_c-TwoCurve 9 : c2onb191v5 56*2139Sjp161948X9-62_c-TwoCurve 10 : c2pnb208w1 57*2139Sjp161948X9-62_c-TwoCurve 11 : c2tnb239v1 58*2139Sjp161948X9-62_c-TwoCurve 12 : c2tnb239v2 59*2139Sjp161948X9-62_c-TwoCurve 13 : c2tnb239v3 60*2139Sjp161948X9-62_c-TwoCurve 14 : c2onb239v4 61*2139Sjp161948X9-62_c-TwoCurve 15 : c2onb239v5 62*2139Sjp161948X9-62_c-TwoCurve 16 : c2pnb272w1 63*2139Sjp161948X9-62_c-TwoCurve 17 : c2pnb304w1 64*2139Sjp161948X9-62_c-TwoCurve 18 : c2tnb359v1 65*2139Sjp161948X9-62_c-TwoCurve 19 : c2pnb368w1 66*2139Sjp161948X9-62_c-TwoCurve 20 : c2tnb431r1 670Sstevel@tonic-gate!Alias primeCurve X9-62_ellipticCurve 1 680Sstevel@tonic-gateX9-62_primeCurve 1 : prime192v1 690Sstevel@tonic-gateX9-62_primeCurve 2 : prime192v2 700Sstevel@tonic-gateX9-62_primeCurve 3 : prime192v3 710Sstevel@tonic-gateX9-62_primeCurve 4 : prime239v1 720Sstevel@tonic-gateX9-62_primeCurve 5 : prime239v2 730Sstevel@tonic-gateX9-62_primeCurve 6 : prime239v3 740Sstevel@tonic-gateX9-62_primeCurve 7 : prime256v1 750Sstevel@tonic-gate!Alias id-ecSigType ansi-X9-62 4 760Sstevel@tonic-gate!global 770Sstevel@tonic-gateX9-62_id-ecSigType 1 : ecdsa-with-SHA1 780Sstevel@tonic-gate 79*2139Sjp161948# SECG curve OIDs from "SEC 2: Recommended Elliptic Curve Domain Parameters" 80*2139Sjp161948# (http://www.secg.org/) 81*2139Sjp161948!Alias secg_ellipticCurve certicom-arc 0 82*2139Sjp161948# SECG prime curves OIDs 83*2139Sjp161948secg-ellipticCurve 6 : secp112r1 84*2139Sjp161948secg-ellipticCurve 7 : secp112r2 85*2139Sjp161948secg-ellipticCurve 28 : secp128r1 86*2139Sjp161948secg-ellipticCurve 29 : secp128r2 87*2139Sjp161948secg-ellipticCurve 9 : secp160k1 88*2139Sjp161948secg-ellipticCurve 8 : secp160r1 89*2139Sjp161948secg-ellipticCurve 30 : secp160r2 90*2139Sjp161948secg-ellipticCurve 31 : secp192k1 91*2139Sjp161948# NOTE: the curve secp192r1 is the same as prime192v1 defined above 92*2139Sjp161948# and is therefore omitted 93*2139Sjp161948secg-ellipticCurve 32 : secp224k1 94*2139Sjp161948secg-ellipticCurve 33 : secp224r1 95*2139Sjp161948secg-ellipticCurve 10 : secp256k1 96*2139Sjp161948# NOTE: the curve secp256r1 is the same as prime256v1 defined above 97*2139Sjp161948# and is therefore omitted 98*2139Sjp161948secg-ellipticCurve 34 : secp384r1 99*2139Sjp161948secg-ellipticCurve 35 : secp521r1 100*2139Sjp161948# SECG characteristic two curves OIDs 101*2139Sjp161948secg-ellipticCurve 4 : sect113r1 102*2139Sjp161948secg-ellipticCurve 5 : sect113r2 103*2139Sjp161948secg-ellipticCurve 22 : sect131r1 104*2139Sjp161948secg-ellipticCurve 23 : sect131r2 105*2139Sjp161948secg-ellipticCurve 1 : sect163k1 106*2139Sjp161948secg-ellipticCurve 2 : sect163r1 107*2139Sjp161948secg-ellipticCurve 15 : sect163r2 108*2139Sjp161948secg-ellipticCurve 24 : sect193r1 109*2139Sjp161948secg-ellipticCurve 25 : sect193r2 110*2139Sjp161948secg-ellipticCurve 26 : sect233k1 111*2139Sjp161948secg-ellipticCurve 27 : sect233r1 112*2139Sjp161948secg-ellipticCurve 3 : sect239k1 113*2139Sjp161948secg-ellipticCurve 16 : sect283k1 114*2139Sjp161948secg-ellipticCurve 17 : sect283r1 115*2139Sjp161948secg-ellipticCurve 36 : sect409k1 116*2139Sjp161948secg-ellipticCurve 37 : sect409r1 117*2139Sjp161948secg-ellipticCurve 38 : sect571k1 118*2139Sjp161948secg-ellipticCurve 39 : sect571r1 119*2139Sjp161948 120*2139Sjp161948# WAP/TLS curve OIDs (http://www.wapforum.org/) 121*2139Sjp161948!Alias wap-wsg-idm-ecid wap-wsg 4 122*2139Sjp161948wap-wsg-idm-ecid 1 : wap-wsg-idm-ecid-wtls1 123*2139Sjp161948wap-wsg-idm-ecid 3 : wap-wsg-idm-ecid-wtls3 124*2139Sjp161948wap-wsg-idm-ecid 4 : wap-wsg-idm-ecid-wtls4 125*2139Sjp161948wap-wsg-idm-ecid 5 : wap-wsg-idm-ecid-wtls5 126*2139Sjp161948wap-wsg-idm-ecid 6 : wap-wsg-idm-ecid-wtls6 127*2139Sjp161948wap-wsg-idm-ecid 7 : wap-wsg-idm-ecid-wtls7 128*2139Sjp161948wap-wsg-idm-ecid 8 : wap-wsg-idm-ecid-wtls8 129*2139Sjp161948wap-wsg-idm-ecid 9 : wap-wsg-idm-ecid-wtls9 130*2139Sjp161948wap-wsg-idm-ecid 10 : wap-wsg-idm-ecid-wtls10 131*2139Sjp161948wap-wsg-idm-ecid 11 : wap-wsg-idm-ecid-wtls11 132*2139Sjp161948wap-wsg-idm-ecid 12 : wap-wsg-idm-ecid-wtls12 1330Sstevel@tonic-gate 1340Sstevel@tonic-gate 1350Sstevel@tonic-gateISO-US 113533 7 66 10 : CAST5-CBC : cast5-cbc 1360Sstevel@tonic-gate : CAST5-ECB : cast5-ecb 1370Sstevel@tonic-gate!Cname cast5-cfb64 1380Sstevel@tonic-gate : CAST5-CFB : cast5-cfb 1390Sstevel@tonic-gate!Cname cast5-ofb64 1400Sstevel@tonic-gate : CAST5-OFB : cast5-ofb 1410Sstevel@tonic-gate!Cname pbeWithMD5AndCast5-CBC 1420Sstevel@tonic-gateISO-US 113533 7 66 12 : : pbeWithMD5AndCast5CBC 1430Sstevel@tonic-gate 1440Sstevel@tonic-gateISO-US 113549 : rsadsi : RSA Data Security, Inc. 1450Sstevel@tonic-gate 1460Sstevel@tonic-gatersadsi 1 : pkcs : RSA Data Security, Inc. PKCS 1470Sstevel@tonic-gate 1480Sstevel@tonic-gatepkcs 1 : pkcs1 1490Sstevel@tonic-gatepkcs1 1 : : rsaEncryption 1500Sstevel@tonic-gatepkcs1 2 : RSA-MD2 : md2WithRSAEncryption 1510Sstevel@tonic-gatepkcs1 3 : RSA-MD4 : md4WithRSAEncryption 1520Sstevel@tonic-gatepkcs1 4 : RSA-MD5 : md5WithRSAEncryption 1530Sstevel@tonic-gatepkcs1 5 : RSA-SHA1 : sha1WithRSAEncryption 154*2139Sjp161948# According to PKCS #1 version 2.1 155*2139Sjp161948pkcs1 11 : RSA-SHA256 : sha256WithRSAEncryption 156*2139Sjp161948pkcs1 12 : RSA-SHA384 : sha384WithRSAEncryption 157*2139Sjp161948pkcs1 13 : RSA-SHA512 : sha512WithRSAEncryption 158*2139Sjp161948pkcs1 14 : RSA-SHA224 : sha224WithRSAEncryption 1590Sstevel@tonic-gate 1600Sstevel@tonic-gatepkcs 3 : pkcs3 1610Sstevel@tonic-gatepkcs3 1 : : dhKeyAgreement 1620Sstevel@tonic-gate 1630Sstevel@tonic-gatepkcs 5 : pkcs5 1640Sstevel@tonic-gatepkcs5 1 : PBE-MD2-DES : pbeWithMD2AndDES-CBC 1650Sstevel@tonic-gatepkcs5 3 : PBE-MD5-DES : pbeWithMD5AndDES-CBC 1660Sstevel@tonic-gatepkcs5 4 : PBE-MD2-RC2-64 : pbeWithMD2AndRC2-CBC 1670Sstevel@tonic-gatepkcs5 6 : PBE-MD5-RC2-64 : pbeWithMD5AndRC2-CBC 1680Sstevel@tonic-gatepkcs5 10 : PBE-SHA1-DES : pbeWithSHA1AndDES-CBC 1690Sstevel@tonic-gatepkcs5 11 : PBE-SHA1-RC2-64 : pbeWithSHA1AndRC2-CBC 1700Sstevel@tonic-gate!Cname id_pbkdf2 1710Sstevel@tonic-gatepkcs5 12 : : PBKDF2 1720Sstevel@tonic-gate!Cname pbes2 1730Sstevel@tonic-gatepkcs5 13 : : PBES2 1740Sstevel@tonic-gate!Cname pbmac1 1750Sstevel@tonic-gatepkcs5 14 : : PBMAC1 1760Sstevel@tonic-gate 1770Sstevel@tonic-gatepkcs 7 : pkcs7 1780Sstevel@tonic-gatepkcs7 1 : : pkcs7-data 1790Sstevel@tonic-gate!Cname pkcs7-signed 1800Sstevel@tonic-gatepkcs7 2 : : pkcs7-signedData 1810Sstevel@tonic-gate!Cname pkcs7-enveloped 1820Sstevel@tonic-gatepkcs7 3 : : pkcs7-envelopedData 1830Sstevel@tonic-gate!Cname pkcs7-signedAndEnveloped 1840Sstevel@tonic-gatepkcs7 4 : : pkcs7-signedAndEnvelopedData 1850Sstevel@tonic-gate!Cname pkcs7-digest 1860Sstevel@tonic-gatepkcs7 5 : : pkcs7-digestData 1870Sstevel@tonic-gate!Cname pkcs7-encrypted 1880Sstevel@tonic-gatepkcs7 6 : : pkcs7-encryptedData 1890Sstevel@tonic-gate 1900Sstevel@tonic-gatepkcs 9 : pkcs9 1910Sstevel@tonic-gate!module pkcs9 1920Sstevel@tonic-gatepkcs9 1 : : emailAddress 1930Sstevel@tonic-gatepkcs9 2 : : unstructuredName 1940Sstevel@tonic-gatepkcs9 3 : : contentType 1950Sstevel@tonic-gatepkcs9 4 : : messageDigest 1960Sstevel@tonic-gatepkcs9 5 : : signingTime 1970Sstevel@tonic-gatepkcs9 6 : : countersignature 1980Sstevel@tonic-gatepkcs9 7 : : challengePassword 1990Sstevel@tonic-gatepkcs9 8 : : unstructuredAddress 2000Sstevel@tonic-gate!Cname extCertAttributes 2010Sstevel@tonic-gatepkcs9 9 : : extendedCertificateAttributes 2020Sstevel@tonic-gate!global 2030Sstevel@tonic-gate 2040Sstevel@tonic-gate!Cname ext-req 2050Sstevel@tonic-gatepkcs9 14 : extReq : Extension Request 2060Sstevel@tonic-gate 2070Sstevel@tonic-gate!Cname SMIMECapabilities 2080Sstevel@tonic-gatepkcs9 15 : SMIME-CAPS : S/MIME Capabilities 2090Sstevel@tonic-gate 2100Sstevel@tonic-gate# S/MIME 2110Sstevel@tonic-gate!Cname SMIME 2120Sstevel@tonic-gatepkcs9 16 : SMIME : S/MIME 2130Sstevel@tonic-gateSMIME 0 : id-smime-mod 2140Sstevel@tonic-gateSMIME 1 : id-smime-ct 2150Sstevel@tonic-gateSMIME 2 : id-smime-aa 2160Sstevel@tonic-gateSMIME 3 : id-smime-alg 2170Sstevel@tonic-gateSMIME 4 : id-smime-cd 2180Sstevel@tonic-gateSMIME 5 : id-smime-spq 2190Sstevel@tonic-gateSMIME 6 : id-smime-cti 2200Sstevel@tonic-gate 2210Sstevel@tonic-gate# S/MIME Modules 2220Sstevel@tonic-gateid-smime-mod 1 : id-smime-mod-cms 2230Sstevel@tonic-gateid-smime-mod 2 : id-smime-mod-ess 2240Sstevel@tonic-gateid-smime-mod 3 : id-smime-mod-oid 2250Sstevel@tonic-gateid-smime-mod 4 : id-smime-mod-msg-v3 2260Sstevel@tonic-gateid-smime-mod 5 : id-smime-mod-ets-eSignature-88 2270Sstevel@tonic-gateid-smime-mod 6 : id-smime-mod-ets-eSignature-97 2280Sstevel@tonic-gateid-smime-mod 7 : id-smime-mod-ets-eSigPolicy-88 2290Sstevel@tonic-gateid-smime-mod 8 : id-smime-mod-ets-eSigPolicy-97 2300Sstevel@tonic-gate 2310Sstevel@tonic-gate# S/MIME Content Types 2320Sstevel@tonic-gateid-smime-ct 1 : id-smime-ct-receipt 2330Sstevel@tonic-gateid-smime-ct 2 : id-smime-ct-authData 2340Sstevel@tonic-gateid-smime-ct 3 : id-smime-ct-publishCert 2350Sstevel@tonic-gateid-smime-ct 4 : id-smime-ct-TSTInfo 2360Sstevel@tonic-gateid-smime-ct 5 : id-smime-ct-TDTInfo 2370Sstevel@tonic-gateid-smime-ct 6 : id-smime-ct-contentInfo 2380Sstevel@tonic-gateid-smime-ct 7 : id-smime-ct-DVCSRequestData 2390Sstevel@tonic-gateid-smime-ct 8 : id-smime-ct-DVCSResponseData 2400Sstevel@tonic-gate 2410Sstevel@tonic-gate# S/MIME Attributes 2420Sstevel@tonic-gateid-smime-aa 1 : id-smime-aa-receiptRequest 2430Sstevel@tonic-gateid-smime-aa 2 : id-smime-aa-securityLabel 2440Sstevel@tonic-gateid-smime-aa 3 : id-smime-aa-mlExpandHistory 2450Sstevel@tonic-gateid-smime-aa 4 : id-smime-aa-contentHint 2460Sstevel@tonic-gateid-smime-aa 5 : id-smime-aa-msgSigDigest 2470Sstevel@tonic-gate# obsolete 2480Sstevel@tonic-gateid-smime-aa 6 : id-smime-aa-encapContentType 2490Sstevel@tonic-gateid-smime-aa 7 : id-smime-aa-contentIdentifier 2500Sstevel@tonic-gate# obsolete 2510Sstevel@tonic-gateid-smime-aa 8 : id-smime-aa-macValue 2520Sstevel@tonic-gateid-smime-aa 9 : id-smime-aa-equivalentLabels 2530Sstevel@tonic-gateid-smime-aa 10 : id-smime-aa-contentReference 2540Sstevel@tonic-gateid-smime-aa 11 : id-smime-aa-encrypKeyPref 2550Sstevel@tonic-gateid-smime-aa 12 : id-smime-aa-signingCertificate 2560Sstevel@tonic-gateid-smime-aa 13 : id-smime-aa-smimeEncryptCerts 2570Sstevel@tonic-gateid-smime-aa 14 : id-smime-aa-timeStampToken 2580Sstevel@tonic-gateid-smime-aa 15 : id-smime-aa-ets-sigPolicyId 2590Sstevel@tonic-gateid-smime-aa 16 : id-smime-aa-ets-commitmentType 2600Sstevel@tonic-gateid-smime-aa 17 : id-smime-aa-ets-signerLocation 2610Sstevel@tonic-gateid-smime-aa 18 : id-smime-aa-ets-signerAttr 2620Sstevel@tonic-gateid-smime-aa 19 : id-smime-aa-ets-otherSigCert 2630Sstevel@tonic-gateid-smime-aa 20 : id-smime-aa-ets-contentTimestamp 2640Sstevel@tonic-gateid-smime-aa 21 : id-smime-aa-ets-CertificateRefs 2650Sstevel@tonic-gateid-smime-aa 22 : id-smime-aa-ets-RevocationRefs 2660Sstevel@tonic-gateid-smime-aa 23 : id-smime-aa-ets-certValues 2670Sstevel@tonic-gateid-smime-aa 24 : id-smime-aa-ets-revocationValues 2680Sstevel@tonic-gateid-smime-aa 25 : id-smime-aa-ets-escTimeStamp 2690Sstevel@tonic-gateid-smime-aa 26 : id-smime-aa-ets-certCRLTimestamp 2700Sstevel@tonic-gateid-smime-aa 27 : id-smime-aa-ets-archiveTimeStamp 2710Sstevel@tonic-gateid-smime-aa 28 : id-smime-aa-signatureType 2720Sstevel@tonic-gateid-smime-aa 29 : id-smime-aa-dvcs-dvc 2730Sstevel@tonic-gate 2740Sstevel@tonic-gate# S/MIME Algorithm Identifiers 2750Sstevel@tonic-gate# obsolete 2760Sstevel@tonic-gateid-smime-alg 1 : id-smime-alg-ESDHwith3DES 2770Sstevel@tonic-gate# obsolete 2780Sstevel@tonic-gateid-smime-alg 2 : id-smime-alg-ESDHwithRC2 2790Sstevel@tonic-gate# obsolete 2800Sstevel@tonic-gateid-smime-alg 3 : id-smime-alg-3DESwrap 2810Sstevel@tonic-gate# obsolete 2820Sstevel@tonic-gateid-smime-alg 4 : id-smime-alg-RC2wrap 2830Sstevel@tonic-gateid-smime-alg 5 : id-smime-alg-ESDH 2840Sstevel@tonic-gateid-smime-alg 6 : id-smime-alg-CMS3DESwrap 2850Sstevel@tonic-gateid-smime-alg 7 : id-smime-alg-CMSRC2wrap 2860Sstevel@tonic-gate 2870Sstevel@tonic-gate# S/MIME Certificate Distribution 2880Sstevel@tonic-gateid-smime-cd 1 : id-smime-cd-ldap 2890Sstevel@tonic-gate 2900Sstevel@tonic-gate# S/MIME Signature Policy Qualifier 2910Sstevel@tonic-gateid-smime-spq 1 : id-smime-spq-ets-sqt-uri 2920Sstevel@tonic-gateid-smime-spq 2 : id-smime-spq-ets-sqt-unotice 2930Sstevel@tonic-gate 2940Sstevel@tonic-gate# S/MIME Commitment Type Identifier 2950Sstevel@tonic-gateid-smime-cti 1 : id-smime-cti-ets-proofOfOrigin 2960Sstevel@tonic-gateid-smime-cti 2 : id-smime-cti-ets-proofOfReceipt 2970Sstevel@tonic-gateid-smime-cti 3 : id-smime-cti-ets-proofOfDelivery 2980Sstevel@tonic-gateid-smime-cti 4 : id-smime-cti-ets-proofOfSender 2990Sstevel@tonic-gateid-smime-cti 5 : id-smime-cti-ets-proofOfApproval 3000Sstevel@tonic-gateid-smime-cti 6 : id-smime-cti-ets-proofOfCreation 3010Sstevel@tonic-gate 3020Sstevel@tonic-gatepkcs9 20 : : friendlyName 3030Sstevel@tonic-gatepkcs9 21 : : localKeyID 3040Sstevel@tonic-gate!Cname ms-csp-name 3050Sstevel@tonic-gate1 3 6 1 4 1 311 17 1 : CSPName : Microsoft CSP Name 3060Sstevel@tonic-gate!Alias certTypes pkcs9 22 3070Sstevel@tonic-gatecertTypes 1 : : x509Certificate 3080Sstevel@tonic-gatecertTypes 2 : : sdsiCertificate 3090Sstevel@tonic-gate!Alias crlTypes pkcs9 23 3100Sstevel@tonic-gatecrlTypes 1 : : x509Crl 3110Sstevel@tonic-gate 3120Sstevel@tonic-gate!Alias pkcs12 pkcs 12 3130Sstevel@tonic-gate!Alias pkcs12-pbeids pkcs12 1 3140Sstevel@tonic-gate 3150Sstevel@tonic-gate!Cname pbe-WithSHA1And128BitRC4 3160Sstevel@tonic-gatepkcs12-pbeids 1 : PBE-SHA1-RC4-128 : pbeWithSHA1And128BitRC4 3170Sstevel@tonic-gate!Cname pbe-WithSHA1And40BitRC4 3180Sstevel@tonic-gatepkcs12-pbeids 2 : PBE-SHA1-RC4-40 : pbeWithSHA1And40BitRC4 3190Sstevel@tonic-gate!Cname pbe-WithSHA1And3_Key_TripleDES-CBC 3200Sstevel@tonic-gatepkcs12-pbeids 3 : PBE-SHA1-3DES : pbeWithSHA1And3-KeyTripleDES-CBC 3210Sstevel@tonic-gate!Cname pbe-WithSHA1And2_Key_TripleDES-CBC 3220Sstevel@tonic-gatepkcs12-pbeids 4 : PBE-SHA1-2DES : pbeWithSHA1And2-KeyTripleDES-CBC 3230Sstevel@tonic-gate!Cname pbe-WithSHA1And128BitRC2-CBC 3240Sstevel@tonic-gatepkcs12-pbeids 5 : PBE-SHA1-RC2-128 : pbeWithSHA1And128BitRC2-CBC 3250Sstevel@tonic-gate!Cname pbe-WithSHA1And40BitRC2-CBC 3260Sstevel@tonic-gatepkcs12-pbeids 6 : PBE-SHA1-RC2-40 : pbeWithSHA1And40BitRC2-CBC 3270Sstevel@tonic-gate 3280Sstevel@tonic-gate!Alias pkcs12-Version1 pkcs12 10 3290Sstevel@tonic-gate!Alias pkcs12-BagIds pkcs12-Version1 1 3300Sstevel@tonic-gatepkcs12-BagIds 1 : : keyBag 3310Sstevel@tonic-gatepkcs12-BagIds 2 : : pkcs8ShroudedKeyBag 3320Sstevel@tonic-gatepkcs12-BagIds 3 : : certBag 3330Sstevel@tonic-gatepkcs12-BagIds 4 : : crlBag 3340Sstevel@tonic-gatepkcs12-BagIds 5 : : secretBag 3350Sstevel@tonic-gatepkcs12-BagIds 6 : : safeContentsBag 3360Sstevel@tonic-gate 3370Sstevel@tonic-gatersadsi 2 2 : MD2 : md2 3380Sstevel@tonic-gatersadsi 2 4 : MD4 : md4 3390Sstevel@tonic-gatersadsi 2 5 : MD5 : md5 3400Sstevel@tonic-gate : MD5-SHA1 : md5-sha1 3410Sstevel@tonic-gatersadsi 2 7 : : hmacWithSHA1 3420Sstevel@tonic-gatersadsi 3 2 : RC2-CBC : rc2-cbc 3430Sstevel@tonic-gate : RC2-ECB : rc2-ecb 3440Sstevel@tonic-gate!Cname rc2-cfb64 3450Sstevel@tonic-gate : RC2-CFB : rc2-cfb 3460Sstevel@tonic-gate!Cname rc2-ofb64 3470Sstevel@tonic-gate : RC2-OFB : rc2-ofb 3480Sstevel@tonic-gate : RC2-40-CBC : rc2-40-cbc 3490Sstevel@tonic-gate : RC2-64-CBC : rc2-64-cbc 3500Sstevel@tonic-gatersadsi 3 4 : RC4 : rc4 3510Sstevel@tonic-gate : RC4-40 : rc4-40 3520Sstevel@tonic-gatersadsi 3 7 : DES-EDE3-CBC : des-ede3-cbc 3530Sstevel@tonic-gatersadsi 3 8 : RC5-CBC : rc5-cbc 3540Sstevel@tonic-gate : RC5-ECB : rc5-ecb 3550Sstevel@tonic-gate!Cname rc5-cfb64 3560Sstevel@tonic-gate : RC5-CFB : rc5-cfb 3570Sstevel@tonic-gate!Cname rc5-ofb64 3580Sstevel@tonic-gate : RC5-OFB : rc5-ofb 3590Sstevel@tonic-gate 3600Sstevel@tonic-gate!Cname ms-ext-req 3610Sstevel@tonic-gate1 3 6 1 4 1 311 2 1 14 : msExtReq : Microsoft Extension Request 3620Sstevel@tonic-gate!Cname ms-code-ind 3630Sstevel@tonic-gate1 3 6 1 4 1 311 2 1 21 : msCodeInd : Microsoft Individual Code Signing 3640Sstevel@tonic-gate!Cname ms-code-com 3650Sstevel@tonic-gate1 3 6 1 4 1 311 2 1 22 : msCodeCom : Microsoft Commercial Code Signing 3660Sstevel@tonic-gate!Cname ms-ctl-sign 3670Sstevel@tonic-gate1 3 6 1 4 1 311 10 3 1 : msCTLSign : Microsoft Trust List Signing 3680Sstevel@tonic-gate!Cname ms-sgc 3690Sstevel@tonic-gate1 3 6 1 4 1 311 10 3 3 : msSGC : Microsoft Server Gated Crypto 3700Sstevel@tonic-gate!Cname ms-efs 3710Sstevel@tonic-gate1 3 6 1 4 1 311 10 3 4 : msEFS : Microsoft Encrypted File System 3720Sstevel@tonic-gate!Cname ms-smartcard-login 3730Sstevel@tonic-gate1 3 6 1 4 1 311 20 2 2 : msSmartcardLogin : Microsoft Smartcardlogin 3740Sstevel@tonic-gate!Cname ms-upn 3750Sstevel@tonic-gate1 3 6 1 4 1 311 20 2 3 : msUPN : Microsoft Universal Principal Name 3760Sstevel@tonic-gate 3770Sstevel@tonic-gate1 3 6 1 4 1 188 7 1 1 2 : IDEA-CBC : idea-cbc 3780Sstevel@tonic-gate : IDEA-ECB : idea-ecb 3790Sstevel@tonic-gate!Cname idea-cfb64 3800Sstevel@tonic-gate : IDEA-CFB : idea-cfb 3810Sstevel@tonic-gate!Cname idea-ofb64 3820Sstevel@tonic-gate : IDEA-OFB : idea-ofb 3830Sstevel@tonic-gate 3840Sstevel@tonic-gate1 3 6 1 4 1 3029 1 2 : BF-CBC : bf-cbc 3850Sstevel@tonic-gate : BF-ECB : bf-ecb 3860Sstevel@tonic-gate!Cname bf-cfb64 3870Sstevel@tonic-gate : BF-CFB : bf-cfb 3880Sstevel@tonic-gate!Cname bf-ofb64 3890Sstevel@tonic-gate : BF-OFB : bf-ofb 3900Sstevel@tonic-gate 3910Sstevel@tonic-gate!Cname id-pkix 3920Sstevel@tonic-gate1 3 6 1 5 5 7 : PKIX 3930Sstevel@tonic-gate 3940Sstevel@tonic-gate# PKIX Arcs 3950Sstevel@tonic-gateid-pkix 0 : id-pkix-mod 3960Sstevel@tonic-gateid-pkix 1 : id-pe 3970Sstevel@tonic-gateid-pkix 2 : id-qt 3980Sstevel@tonic-gateid-pkix 3 : id-kp 3990Sstevel@tonic-gateid-pkix 4 : id-it 4000Sstevel@tonic-gateid-pkix 5 : id-pkip 4010Sstevel@tonic-gateid-pkix 6 : id-alg 4020Sstevel@tonic-gateid-pkix 7 : id-cmc 4030Sstevel@tonic-gateid-pkix 8 : id-on 4040Sstevel@tonic-gateid-pkix 9 : id-pda 4050Sstevel@tonic-gateid-pkix 10 : id-aca 4060Sstevel@tonic-gateid-pkix 11 : id-qcs 4070Sstevel@tonic-gateid-pkix 12 : id-cct 408*2139Sjp161948id-pkix 21 : id-ppl 4090Sstevel@tonic-gateid-pkix 48 : id-ad 4100Sstevel@tonic-gate 4110Sstevel@tonic-gate# PKIX Modules 4120Sstevel@tonic-gateid-pkix-mod 1 : id-pkix1-explicit-88 4130Sstevel@tonic-gateid-pkix-mod 2 : id-pkix1-implicit-88 4140Sstevel@tonic-gateid-pkix-mod 3 : id-pkix1-explicit-93 4150Sstevel@tonic-gateid-pkix-mod 4 : id-pkix1-implicit-93 4160Sstevel@tonic-gateid-pkix-mod 5 : id-mod-crmf 4170Sstevel@tonic-gateid-pkix-mod 6 : id-mod-cmc 4180Sstevel@tonic-gateid-pkix-mod 7 : id-mod-kea-profile-88 4190Sstevel@tonic-gateid-pkix-mod 8 : id-mod-kea-profile-93 4200Sstevel@tonic-gateid-pkix-mod 9 : id-mod-cmp 4210Sstevel@tonic-gateid-pkix-mod 10 : id-mod-qualified-cert-88 4220Sstevel@tonic-gateid-pkix-mod 11 : id-mod-qualified-cert-93 4230Sstevel@tonic-gateid-pkix-mod 12 : id-mod-attribute-cert 4240Sstevel@tonic-gateid-pkix-mod 13 : id-mod-timestamp-protocol 4250Sstevel@tonic-gateid-pkix-mod 14 : id-mod-ocsp 4260Sstevel@tonic-gateid-pkix-mod 15 : id-mod-dvcs 4270Sstevel@tonic-gateid-pkix-mod 16 : id-mod-cmp2000 4280Sstevel@tonic-gate 4290Sstevel@tonic-gate# PKIX Private Extensions 4300Sstevel@tonic-gate!Cname info-access 4310Sstevel@tonic-gateid-pe 1 : authorityInfoAccess : Authority Information Access 4320Sstevel@tonic-gateid-pe 2 : biometricInfo : Biometric Info 4330Sstevel@tonic-gateid-pe 3 : qcStatements 4340Sstevel@tonic-gateid-pe 4 : ac-auditEntity 4350Sstevel@tonic-gateid-pe 5 : ac-targeting 4360Sstevel@tonic-gateid-pe 6 : aaControls 437*2139Sjp161948id-pe 7 : sbgp-ipAddrBlock 438*2139Sjp161948id-pe 8 : sbgp-autonomousSysNum 439*2139Sjp161948id-pe 9 : sbgp-routerIdentifier 4400Sstevel@tonic-gateid-pe 10 : ac-proxying 4410Sstevel@tonic-gate!Cname sinfo-access 4420Sstevel@tonic-gateid-pe 11 : subjectInfoAccess : Subject Information Access 443*2139Sjp161948id-pe 14 : proxyCertInfo : Proxy Certificate Information 4440Sstevel@tonic-gate 4450Sstevel@tonic-gate# PKIX policyQualifiers for Internet policy qualifiers 4460Sstevel@tonic-gateid-qt 1 : id-qt-cps : Policy Qualifier CPS 4470Sstevel@tonic-gateid-qt 2 : id-qt-unotice : Policy Qualifier User Notice 4480Sstevel@tonic-gateid-qt 3 : textNotice 4490Sstevel@tonic-gate 4500Sstevel@tonic-gate# PKIX key purpose identifiers 4510Sstevel@tonic-gate!Cname server-auth 4520Sstevel@tonic-gateid-kp 1 : serverAuth : TLS Web Server Authentication 4530Sstevel@tonic-gate!Cname client-auth 4540Sstevel@tonic-gateid-kp 2 : clientAuth : TLS Web Client Authentication 4550Sstevel@tonic-gate!Cname code-sign 4560Sstevel@tonic-gateid-kp 3 : codeSigning : Code Signing 4570Sstevel@tonic-gate!Cname email-protect 4580Sstevel@tonic-gateid-kp 4 : emailProtection : E-mail Protection 4590Sstevel@tonic-gateid-kp 5 : ipsecEndSystem : IPSec End System 4600Sstevel@tonic-gateid-kp 6 : ipsecTunnel : IPSec Tunnel 4610Sstevel@tonic-gateid-kp 7 : ipsecUser : IPSec User 4620Sstevel@tonic-gate!Cname time-stamp 4630Sstevel@tonic-gateid-kp 8 : timeStamping : Time Stamping 4640Sstevel@tonic-gate# From OCSP spec RFC2560 4650Sstevel@tonic-gate!Cname OCSP-sign 4660Sstevel@tonic-gateid-kp 9 : OCSPSigning : OCSP Signing 4670Sstevel@tonic-gateid-kp 10 : DVCS : dvcs 4680Sstevel@tonic-gate 4690Sstevel@tonic-gate# CMP information types 4700Sstevel@tonic-gateid-it 1 : id-it-caProtEncCert 4710Sstevel@tonic-gateid-it 2 : id-it-signKeyPairTypes 4720Sstevel@tonic-gateid-it 3 : id-it-encKeyPairTypes 4730Sstevel@tonic-gateid-it 4 : id-it-preferredSymmAlg 4740Sstevel@tonic-gateid-it 5 : id-it-caKeyUpdateInfo 4750Sstevel@tonic-gateid-it 6 : id-it-currentCRL 4760Sstevel@tonic-gateid-it 7 : id-it-unsupportedOIDs 4770Sstevel@tonic-gate# obsolete 4780Sstevel@tonic-gateid-it 8 : id-it-subscriptionRequest 4790Sstevel@tonic-gate# obsolete 4800Sstevel@tonic-gateid-it 9 : id-it-subscriptionResponse 4810Sstevel@tonic-gateid-it 10 : id-it-keyPairParamReq 4820Sstevel@tonic-gateid-it 11 : id-it-keyPairParamRep 4830Sstevel@tonic-gateid-it 12 : id-it-revPassphrase 4840Sstevel@tonic-gateid-it 13 : id-it-implicitConfirm 4850Sstevel@tonic-gateid-it 14 : id-it-confirmWaitTime 4860Sstevel@tonic-gateid-it 15 : id-it-origPKIMessage 4870Sstevel@tonic-gate 4880Sstevel@tonic-gate# CRMF registration 4890Sstevel@tonic-gateid-pkip 1 : id-regCtrl 4900Sstevel@tonic-gateid-pkip 2 : id-regInfo 4910Sstevel@tonic-gate 4920Sstevel@tonic-gate# CRMF registration controls 4930Sstevel@tonic-gateid-regCtrl 1 : id-regCtrl-regToken 4940Sstevel@tonic-gateid-regCtrl 2 : id-regCtrl-authenticator 4950Sstevel@tonic-gateid-regCtrl 3 : id-regCtrl-pkiPublicationInfo 4960Sstevel@tonic-gateid-regCtrl 4 : id-regCtrl-pkiArchiveOptions 4970Sstevel@tonic-gateid-regCtrl 5 : id-regCtrl-oldCertID 4980Sstevel@tonic-gateid-regCtrl 6 : id-regCtrl-protocolEncrKey 4990Sstevel@tonic-gate 5000Sstevel@tonic-gate# CRMF registration information 5010Sstevel@tonic-gateid-regInfo 1 : id-regInfo-utf8Pairs 5020Sstevel@tonic-gateid-regInfo 2 : id-regInfo-certReq 5030Sstevel@tonic-gate 5040Sstevel@tonic-gate# algorithms 5050Sstevel@tonic-gateid-alg 1 : id-alg-des40 5060Sstevel@tonic-gateid-alg 2 : id-alg-noSignature 5070Sstevel@tonic-gateid-alg 3 : id-alg-dh-sig-hmac-sha1 5080Sstevel@tonic-gateid-alg 4 : id-alg-dh-pop 5090Sstevel@tonic-gate 5100Sstevel@tonic-gate# CMC controls 5110Sstevel@tonic-gateid-cmc 1 : id-cmc-statusInfo 5120Sstevel@tonic-gateid-cmc 2 : id-cmc-identification 5130Sstevel@tonic-gateid-cmc 3 : id-cmc-identityProof 5140Sstevel@tonic-gateid-cmc 4 : id-cmc-dataReturn 5150Sstevel@tonic-gateid-cmc 5 : id-cmc-transactionId 5160Sstevel@tonic-gateid-cmc 6 : id-cmc-senderNonce 5170Sstevel@tonic-gateid-cmc 7 : id-cmc-recipientNonce 5180Sstevel@tonic-gateid-cmc 8 : id-cmc-addExtensions 5190Sstevel@tonic-gateid-cmc 9 : id-cmc-encryptedPOP 5200Sstevel@tonic-gateid-cmc 10 : id-cmc-decryptedPOP 5210Sstevel@tonic-gateid-cmc 11 : id-cmc-lraPOPWitness 5220Sstevel@tonic-gateid-cmc 15 : id-cmc-getCert 5230Sstevel@tonic-gateid-cmc 16 : id-cmc-getCRL 5240Sstevel@tonic-gateid-cmc 17 : id-cmc-revokeRequest 5250Sstevel@tonic-gateid-cmc 18 : id-cmc-regInfo 5260Sstevel@tonic-gateid-cmc 19 : id-cmc-responseInfo 5270Sstevel@tonic-gateid-cmc 21 : id-cmc-queryPending 5280Sstevel@tonic-gateid-cmc 22 : id-cmc-popLinkRandom 5290Sstevel@tonic-gateid-cmc 23 : id-cmc-popLinkWitness 5300Sstevel@tonic-gateid-cmc 24 : id-cmc-confirmCertAcceptance 5310Sstevel@tonic-gate 5320Sstevel@tonic-gate# other names 5330Sstevel@tonic-gateid-on 1 : id-on-personalData 5340Sstevel@tonic-gate 5350Sstevel@tonic-gate# personal data attributes 5360Sstevel@tonic-gateid-pda 1 : id-pda-dateOfBirth 5370Sstevel@tonic-gateid-pda 2 : id-pda-placeOfBirth 5380Sstevel@tonic-gateid-pda 3 : id-pda-gender 5390Sstevel@tonic-gateid-pda 4 : id-pda-countryOfCitizenship 5400Sstevel@tonic-gateid-pda 5 : id-pda-countryOfResidence 5410Sstevel@tonic-gate 5420Sstevel@tonic-gate# attribute certificate attributes 5430Sstevel@tonic-gateid-aca 1 : id-aca-authenticationInfo 5440Sstevel@tonic-gateid-aca 2 : id-aca-accessIdentity 5450Sstevel@tonic-gateid-aca 3 : id-aca-chargingIdentity 5460Sstevel@tonic-gateid-aca 4 : id-aca-group 5470Sstevel@tonic-gate# attention : the following seems to be obsolete, replace by 'role' 5480Sstevel@tonic-gateid-aca 5 : id-aca-role 5490Sstevel@tonic-gateid-aca 6 : id-aca-encAttrs 5500Sstevel@tonic-gate 5510Sstevel@tonic-gate# qualified certificate statements 5520Sstevel@tonic-gateid-qcs 1 : id-qcs-pkixQCSyntax-v1 5530Sstevel@tonic-gate 5540Sstevel@tonic-gate# CMC content types 5550Sstevel@tonic-gateid-cct 1 : id-cct-crs 5560Sstevel@tonic-gateid-cct 2 : id-cct-PKIData 5570Sstevel@tonic-gateid-cct 3 : id-cct-PKIResponse 5580Sstevel@tonic-gate 559*2139Sjp161948# Predefined Proxy Certificate policy languages 560*2139Sjp161948id-ppl 0 : id-ppl-anyLanguage : Any language 561*2139Sjp161948id-ppl 1 : id-ppl-inheritAll : Inherit all 562*2139Sjp161948id-ppl 2 : id-ppl-independent : Independent 563*2139Sjp161948 5640Sstevel@tonic-gate# access descriptors for authority info access extension 5650Sstevel@tonic-gate!Cname ad-OCSP 5660Sstevel@tonic-gateid-ad 1 : OCSP : OCSP 5670Sstevel@tonic-gate!Cname ad-ca-issuers 5680Sstevel@tonic-gateid-ad 2 : caIssuers : CA Issuers 5690Sstevel@tonic-gate!Cname ad-timeStamping 5700Sstevel@tonic-gateid-ad 3 : ad_timestamping : AD Time Stamping 5710Sstevel@tonic-gate!Cname ad-dvcs 5720Sstevel@tonic-gateid-ad 4 : AD_DVCS : ad dvcs 5730Sstevel@tonic-gate 5740Sstevel@tonic-gate 5750Sstevel@tonic-gate!Alias id-pkix-OCSP ad-OCSP 5760Sstevel@tonic-gate!module id-pkix-OCSP 5770Sstevel@tonic-gate!Cname basic 5780Sstevel@tonic-gateid-pkix-OCSP 1 : basicOCSPResponse : Basic OCSP Response 5790Sstevel@tonic-gateid-pkix-OCSP 2 : Nonce : OCSP Nonce 5800Sstevel@tonic-gateid-pkix-OCSP 3 : CrlID : OCSP CRL ID 5810Sstevel@tonic-gateid-pkix-OCSP 4 : acceptableResponses : Acceptable OCSP Responses 5820Sstevel@tonic-gateid-pkix-OCSP 5 : noCheck : OCSP No Check 5830Sstevel@tonic-gateid-pkix-OCSP 6 : archiveCutoff : OCSP Archive Cutoff 5840Sstevel@tonic-gateid-pkix-OCSP 7 : serviceLocator : OCSP Service Locator 5850Sstevel@tonic-gateid-pkix-OCSP 8 : extendedStatus : Extended OCSP Status 5860Sstevel@tonic-gateid-pkix-OCSP 9 : valid 5870Sstevel@tonic-gateid-pkix-OCSP 10 : path 5880Sstevel@tonic-gateid-pkix-OCSP 11 : trustRoot : Trust Root 5890Sstevel@tonic-gate!global 5900Sstevel@tonic-gate 5910Sstevel@tonic-gate1 3 14 3 2 : algorithm : algorithm 5920Sstevel@tonic-gatealgorithm 3 : RSA-NP-MD5 : md5WithRSA 5930Sstevel@tonic-gatealgorithm 6 : DES-ECB : des-ecb 5940Sstevel@tonic-gatealgorithm 7 : DES-CBC : des-cbc 5950Sstevel@tonic-gate!Cname des-ofb64 5960Sstevel@tonic-gatealgorithm 8 : DES-OFB : des-ofb 5970Sstevel@tonic-gate!Cname des-cfb64 5980Sstevel@tonic-gatealgorithm 9 : DES-CFB : des-cfb 5990Sstevel@tonic-gatealgorithm 11 : rsaSignature 6000Sstevel@tonic-gate!Cname dsa-2 6010Sstevel@tonic-gatealgorithm 12 : DSA-old : dsaEncryption-old 6020Sstevel@tonic-gatealgorithm 13 : DSA-SHA : dsaWithSHA 6030Sstevel@tonic-gatealgorithm 15 : RSA-SHA : shaWithRSAEncryption 6040Sstevel@tonic-gate!Cname des-ede-ecb 6050Sstevel@tonic-gatealgorithm 17 : DES-EDE : des-ede 6060Sstevel@tonic-gate!Cname des-ede3-ecb 6070Sstevel@tonic-gate : DES-EDE3 : des-ede3 6080Sstevel@tonic-gate : DES-EDE-CBC : des-ede-cbc 6090Sstevel@tonic-gate!Cname des-ede-cfb64 6100Sstevel@tonic-gate : DES-EDE-CFB : des-ede-cfb 6110Sstevel@tonic-gate!Cname des-ede3-cfb64 6120Sstevel@tonic-gate : DES-EDE3-CFB : des-ede3-cfb 6130Sstevel@tonic-gate!Cname des-ede-ofb64 6140Sstevel@tonic-gate : DES-EDE-OFB : des-ede-ofb 6150Sstevel@tonic-gate!Cname des-ede3-ofb64 6160Sstevel@tonic-gate : DES-EDE3-OFB : des-ede3-ofb 6170Sstevel@tonic-gate : DESX-CBC : desx-cbc 6180Sstevel@tonic-gatealgorithm 18 : SHA : sha 6190Sstevel@tonic-gatealgorithm 26 : SHA1 : sha1 6200Sstevel@tonic-gate!Cname dsaWithSHA1-2 6210Sstevel@tonic-gatealgorithm 27 : DSA-SHA1-old : dsaWithSHA1-old 6220Sstevel@tonic-gatealgorithm 29 : RSA-SHA1-2 : sha1WithRSA 6230Sstevel@tonic-gate 6240Sstevel@tonic-gate1 3 36 3 2 1 : RIPEMD160 : ripemd160 6250Sstevel@tonic-gate1 3 36 3 3 1 2 : RSA-RIPEMD160 : ripemd160WithRSA 6260Sstevel@tonic-gate 6270Sstevel@tonic-gate!Cname sxnet 6280Sstevel@tonic-gate1 3 101 1 4 1 : SXNetID : Strong Extranet ID 6290Sstevel@tonic-gate 6300Sstevel@tonic-gate2 5 : X500 : directory services (X.500) 6310Sstevel@tonic-gate 6320Sstevel@tonic-gateX500 4 : X509 6330Sstevel@tonic-gateX509 3 : CN : commonName 6340Sstevel@tonic-gateX509 4 : SN : surname 6350Sstevel@tonic-gateX509 5 : : serialNumber 6360Sstevel@tonic-gateX509 6 : C : countryName 6370Sstevel@tonic-gateX509 7 : L : localityName 6380Sstevel@tonic-gateX509 8 : ST : stateOrProvinceName 639*2139Sjp161948X509 9 : : streetAddress 6400Sstevel@tonic-gateX509 10 : O : organizationName 6410Sstevel@tonic-gateX509 11 : OU : organizationalUnitName 6420Sstevel@tonic-gateX509 12 : : title 6430Sstevel@tonic-gateX509 13 : : description 644*2139Sjp161948X509 17 : : postalCode 6450Sstevel@tonic-gateX509 41 : name : name 6460Sstevel@tonic-gateX509 42 : GN : givenName 6470Sstevel@tonic-gateX509 43 : : initials 6480Sstevel@tonic-gateX509 44 : : generationQualifier 6490Sstevel@tonic-gateX509 45 : : x500UniqueIdentifier 6500Sstevel@tonic-gateX509 46 : dnQualifier : dnQualifier 6510Sstevel@tonic-gateX509 65 : : pseudonym 6520Sstevel@tonic-gateX509 72 : role : role 6530Sstevel@tonic-gate 6540Sstevel@tonic-gateX500 8 : X500algorithms : directory services - algorithms 6550Sstevel@tonic-gateX500algorithms 1 1 : RSA : rsa 6560Sstevel@tonic-gateX500algorithms 3 100 : RSA-MDC2 : mdc2WithRSA 6570Sstevel@tonic-gateX500algorithms 3 101 : MDC2 : mdc2 6580Sstevel@tonic-gate 6590Sstevel@tonic-gateX500 29 : id-ce 6600Sstevel@tonic-gate!Cname subject-key-identifier 6610Sstevel@tonic-gateid-ce 14 : subjectKeyIdentifier : X509v3 Subject Key Identifier 6620Sstevel@tonic-gate!Cname key-usage 6630Sstevel@tonic-gateid-ce 15 : keyUsage : X509v3 Key Usage 6640Sstevel@tonic-gate!Cname private-key-usage-period 6650Sstevel@tonic-gateid-ce 16 : privateKeyUsagePeriod : X509v3 Private Key Usage Period 6660Sstevel@tonic-gate!Cname subject-alt-name 6670Sstevel@tonic-gateid-ce 17 : subjectAltName : X509v3 Subject Alternative Name 6680Sstevel@tonic-gate!Cname issuer-alt-name 6690Sstevel@tonic-gateid-ce 18 : issuerAltName : X509v3 Issuer Alternative Name 6700Sstevel@tonic-gate!Cname basic-constraints 6710Sstevel@tonic-gateid-ce 19 : basicConstraints : X509v3 Basic Constraints 6720Sstevel@tonic-gate!Cname crl-number 6730Sstevel@tonic-gateid-ce 20 : crlNumber : X509v3 CRL Number 6740Sstevel@tonic-gate!Cname crl-reason 6750Sstevel@tonic-gateid-ce 21 : CRLReason : X509v3 CRL Reason Code 6760Sstevel@tonic-gate!Cname invalidity-date 6770Sstevel@tonic-gateid-ce 24 : invalidityDate : Invalidity Date 6780Sstevel@tonic-gate!Cname delta-crl 6790Sstevel@tonic-gateid-ce 27 : deltaCRL : X509v3 Delta CRL Indicator 680*2139Sjp161948!Cname name-constraints 681*2139Sjp161948id-ce 30 : nameConstraints : X509v3 Name Constraints 6820Sstevel@tonic-gate!Cname crl-distribution-points 6830Sstevel@tonic-gateid-ce 31 : crlDistributionPoints : X509v3 CRL Distribution Points 6840Sstevel@tonic-gate!Cname certificate-policies 6850Sstevel@tonic-gateid-ce 32 : certificatePolicies : X509v3 Certificate Policies 686*2139Sjp161948!Cname any-policy 687*2139Sjp161948certificate-policies 0 : anyPolicy : X509v3 Any Policy 688*2139Sjp161948!Cname policy-mappings 689*2139Sjp161948id-ce 33 : policyMappings : X509v3 Policy Mappings 6900Sstevel@tonic-gate!Cname authority-key-identifier 6910Sstevel@tonic-gateid-ce 35 : authorityKeyIdentifier : X509v3 Authority Key Identifier 6920Sstevel@tonic-gate!Cname policy-constraints 6930Sstevel@tonic-gateid-ce 36 : policyConstraints : X509v3 Policy Constraints 6940Sstevel@tonic-gate!Cname ext-key-usage 6950Sstevel@tonic-gateid-ce 37 : extendedKeyUsage : X509v3 Extended Key Usage 696*2139Sjp161948!Cname inhibit-any-policy 697*2139Sjp161948id-ce 54 : inhibitAnyPolicy : X509v3 Inhibit Any Policy 6980Sstevel@tonic-gate!Cname target-information 6990Sstevel@tonic-gateid-ce 55 : targetInformation : X509v3 AC Targeting 7000Sstevel@tonic-gate!Cname no-rev-avail 7010Sstevel@tonic-gateid-ce 56 : noRevAvail : X509v3 No Revocation Available 7020Sstevel@tonic-gate 7030Sstevel@tonic-gate!Cname netscape 7040Sstevel@tonic-gate2 16 840 1 113730 : Netscape : Netscape Communications Corp. 7050Sstevel@tonic-gate!Cname netscape-cert-extension 7060Sstevel@tonic-gatenetscape 1 : nsCertExt : Netscape Certificate Extension 7070Sstevel@tonic-gate!Cname netscape-data-type 7080Sstevel@tonic-gatenetscape 2 : nsDataType : Netscape Data Type 7090Sstevel@tonic-gate!Cname netscape-cert-type 7100Sstevel@tonic-gatenetscape-cert-extension 1 : nsCertType : Netscape Cert Type 7110Sstevel@tonic-gate!Cname netscape-base-url 7120Sstevel@tonic-gatenetscape-cert-extension 2 : nsBaseUrl : Netscape Base Url 7130Sstevel@tonic-gate!Cname netscape-revocation-url 7140Sstevel@tonic-gatenetscape-cert-extension 3 : nsRevocationUrl : Netscape Revocation Url 7150Sstevel@tonic-gate!Cname netscape-ca-revocation-url 7160Sstevel@tonic-gatenetscape-cert-extension 4 : nsCaRevocationUrl : Netscape CA Revocation Url 7170Sstevel@tonic-gate!Cname netscape-renewal-url 7180Sstevel@tonic-gatenetscape-cert-extension 7 : nsRenewalUrl : Netscape Renewal Url 7190Sstevel@tonic-gate!Cname netscape-ca-policy-url 7200Sstevel@tonic-gatenetscape-cert-extension 8 : nsCaPolicyUrl : Netscape CA Policy Url 7210Sstevel@tonic-gate!Cname netscape-ssl-server-name 7220Sstevel@tonic-gatenetscape-cert-extension 12 : nsSslServerName : Netscape SSL Server Name 7230Sstevel@tonic-gate!Cname netscape-comment 7240Sstevel@tonic-gatenetscape-cert-extension 13 : nsComment : Netscape Comment 7250Sstevel@tonic-gate!Cname netscape-cert-sequence 7260Sstevel@tonic-gatenetscape-data-type 5 : nsCertSequence : Netscape Certificate Sequence 7270Sstevel@tonic-gate!Cname ns-sgc 7280Sstevel@tonic-gatenetscape 4 1 : nsSGC : Netscape Server Gated Crypto 7290Sstevel@tonic-gate 7300Sstevel@tonic-gate# iso(1) 7310Sstevel@tonic-gateiso 3 : ORG : org 7320Sstevel@tonic-gateorg 6 : DOD : dod 7330Sstevel@tonic-gatedod 1 : IANA : iana 7340Sstevel@tonic-gate!Alias internet iana 7350Sstevel@tonic-gate 7360Sstevel@tonic-gateinternet 1 : directory : Directory 7370Sstevel@tonic-gateinternet 2 : mgmt : Management 7380Sstevel@tonic-gateinternet 3 : experimental : Experimental 7390Sstevel@tonic-gateinternet 4 : private : Private 7400Sstevel@tonic-gateinternet 5 : security : Security 7410Sstevel@tonic-gateinternet 6 : snmpv2 : SNMPv2 7420Sstevel@tonic-gate# Documents refer to "internet 7" as "mail". This however leads to ambiguities 7430Sstevel@tonic-gate# with RFC2798, Section 9.1.3, where "mail" is defined as the short name for 7440Sstevel@tonic-gate# rfc822Mailbox. The short name is therefore here left out for a reason. 7450Sstevel@tonic-gate# Subclasses of "mail", e.g. "MIME MHS" don't consitute a problem, as 7460Sstevel@tonic-gate# references are realized via long name "Mail" (with capital M). 7470Sstevel@tonic-gateinternet 7 : : Mail 7480Sstevel@tonic-gate 7490Sstevel@tonic-gatePrivate 1 : enterprises : Enterprises 7500Sstevel@tonic-gate 7510Sstevel@tonic-gate# RFC 2247 7520Sstevel@tonic-gateEnterprises 1466 344 : dcobject : dcObject 7530Sstevel@tonic-gate 7540Sstevel@tonic-gate# RFC 1495 7550Sstevel@tonic-gateMail 1 : mime-mhs : MIME MHS 7560Sstevel@tonic-gatemime-mhs 1 : mime-mhs-headings : mime-mhs-headings 7570Sstevel@tonic-gatemime-mhs 2 : mime-mhs-bodies : mime-mhs-bodies 7580Sstevel@tonic-gatemime-mhs-headings 1 : id-hex-partial-message : id-hex-partial-message 7590Sstevel@tonic-gatemime-mhs-headings 2 : id-hex-multipart-message : id-hex-multipart-message 7600Sstevel@tonic-gate 7610Sstevel@tonic-gate# What the hell are these OIDs, really? 7620Sstevel@tonic-gate!Cname rle-compression 7630Sstevel@tonic-gate1 1 1 1 666 1 : RLE : run length compression 7640Sstevel@tonic-gate!Cname zlib-compression 7650Sstevel@tonic-gate1 1 1 1 666 2 : ZLIB : zlib compression 7660Sstevel@tonic-gate 7670Sstevel@tonic-gate# AES aka Rijndael 7680Sstevel@tonic-gate 7690Sstevel@tonic-gate!Alias csor 2 16 840 1 101 3 7700Sstevel@tonic-gate!Alias nistAlgorithms csor 4 7710Sstevel@tonic-gate!Alias aes nistAlgorithms 1 7720Sstevel@tonic-gate 7730Sstevel@tonic-gateaes 1 : AES-128-ECB : aes-128-ecb 7740Sstevel@tonic-gateaes 2 : AES-128-CBC : aes-128-cbc 7750Sstevel@tonic-gate!Cname aes-128-ofb128 7760Sstevel@tonic-gateaes 3 : AES-128-OFB : aes-128-ofb 7770Sstevel@tonic-gate!Cname aes-128-cfb128 7780Sstevel@tonic-gateaes 4 : AES-128-CFB : aes-128-cfb 7790Sstevel@tonic-gate 7800Sstevel@tonic-gateaes 21 : AES-192-ECB : aes-192-ecb 7810Sstevel@tonic-gateaes 22 : AES-192-CBC : aes-192-cbc 7820Sstevel@tonic-gate!Cname aes-192-ofb128 7830Sstevel@tonic-gateaes 23 : AES-192-OFB : aes-192-ofb 7840Sstevel@tonic-gate!Cname aes-192-cfb128 7850Sstevel@tonic-gateaes 24 : AES-192-CFB : aes-192-cfb 7860Sstevel@tonic-gate 7870Sstevel@tonic-gateaes 41 : AES-256-ECB : aes-256-ecb 7880Sstevel@tonic-gateaes 42 : AES-256-CBC : aes-256-cbc 7890Sstevel@tonic-gate!Cname aes-256-ofb128 7900Sstevel@tonic-gateaes 43 : AES-256-OFB : aes-256-ofb 7910Sstevel@tonic-gate!Cname aes-256-cfb128 7920Sstevel@tonic-gateaes 44 : AES-256-CFB : aes-256-cfb 7930Sstevel@tonic-gate 794*2139Sjp161948# There are no OIDs for these modes... 795*2139Sjp161948 796*2139Sjp161948 : AES-128-CFB1 : aes-128-cfb1 797*2139Sjp161948 : AES-192-CFB1 : aes-192-cfb1 798*2139Sjp161948 : AES-256-CFB1 : aes-256-cfb1 799*2139Sjp161948 : AES-128-CFB8 : aes-128-cfb8 800*2139Sjp161948 : AES-192-CFB8 : aes-192-cfb8 801*2139Sjp161948 : AES-256-CFB8 : aes-256-cfb8 802*2139Sjp161948 : DES-CFB1 : des-cfb1 803*2139Sjp161948 : DES-CFB8 : des-cfb8 804*2139Sjp161948 : DES-EDE3-CFB1 : des-ede3-cfb1 805*2139Sjp161948 : DES-EDE3-CFB8 : des-ede3-cfb8 806*2139Sjp161948 807*2139Sjp161948# OIDs for SHA224, SHA256, SHA385 and SHA512, according to x9.84. 808*2139Sjp161948!Alias nist_hashalgs nistAlgorithms 2 809*2139Sjp161948nist_hashalgs 1 : SHA256 : sha256 810*2139Sjp161948nist_hashalgs 2 : SHA384 : sha384 811*2139Sjp161948nist_hashalgs 3 : SHA512 : sha512 812*2139Sjp161948nist_hashalgs 4 : SHA224 : sha224 813*2139Sjp161948 8140Sstevel@tonic-gate# Hold instruction CRL entry extension 8150Sstevel@tonic-gate!Cname hold-instruction-code 8160Sstevel@tonic-gateid-ce 23 : holdInstructionCode : Hold Instruction Code 8170Sstevel@tonic-gate!Alias holdInstruction X9-57 2 8180Sstevel@tonic-gate!Cname hold-instruction-none 8190Sstevel@tonic-gateholdInstruction 1 : holdInstructionNone : Hold Instruction None 8200Sstevel@tonic-gate!Cname hold-instruction-call-issuer 8210Sstevel@tonic-gateholdInstruction 2 : holdInstructionCallIssuer : Hold Instruction Call Issuer 8220Sstevel@tonic-gate!Cname hold-instruction-reject 8230Sstevel@tonic-gateholdInstruction 3 : holdInstructionReject : Hold Instruction Reject 8240Sstevel@tonic-gate 825*2139Sjp161948# OID's from ITU-T. Most of this is defined in RFC 1274. A couple of 8260Sstevel@tonic-gate# them are also mentioned in RFC 2247 827*2139Sjp161948itu-t 9 : data 8280Sstevel@tonic-gatedata 2342 : pss 8290Sstevel@tonic-gatepss 19200300 : ucl 8300Sstevel@tonic-gateucl 100 : pilot 8310Sstevel@tonic-gatepilot 1 : : pilotAttributeType 8320Sstevel@tonic-gatepilot 3 : : pilotAttributeSyntax 8330Sstevel@tonic-gatepilot 4 : : pilotObjectClass 8340Sstevel@tonic-gatepilot 10 : : pilotGroups 8350Sstevel@tonic-gatepilotAttributeSyntax 4 : : iA5StringSyntax 8360Sstevel@tonic-gatepilotAttributeSyntax 5 : : caseIgnoreIA5StringSyntax 8370Sstevel@tonic-gatepilotObjectClass 3 : : pilotObject 8380Sstevel@tonic-gatepilotObjectClass 4 : : pilotPerson 8390Sstevel@tonic-gatepilotObjectClass 5 : account 8400Sstevel@tonic-gatepilotObjectClass 6 : document 8410Sstevel@tonic-gatepilotObjectClass 7 : room 8420Sstevel@tonic-gatepilotObjectClass 9 : : documentSeries 8430Sstevel@tonic-gatepilotObjectClass 13 : domain : Domain 8440Sstevel@tonic-gatepilotObjectClass 14 : : rFC822localPart 8450Sstevel@tonic-gatepilotObjectClass 15 : : dNSDomain 8460Sstevel@tonic-gatepilotObjectClass 17 : : domainRelatedObject 8470Sstevel@tonic-gatepilotObjectClass 18 : : friendlyCountry 8480Sstevel@tonic-gatepilotObjectClass 19 : : simpleSecurityObject 8490Sstevel@tonic-gatepilotObjectClass 20 : : pilotOrganization 8500Sstevel@tonic-gatepilotObjectClass 21 : : pilotDSA 8510Sstevel@tonic-gatepilotObjectClass 22 : : qualityLabelledData 8520Sstevel@tonic-gatepilotAttributeType 1 : UID : userId 8530Sstevel@tonic-gatepilotAttributeType 2 : : textEncodedORAddress 8540Sstevel@tonic-gatepilotAttributeType 3 : mail : rfc822Mailbox 8550Sstevel@tonic-gatepilotAttributeType 4 : info 8560Sstevel@tonic-gatepilotAttributeType 5 : : favouriteDrink 8570Sstevel@tonic-gatepilotAttributeType 6 : : roomNumber 8580Sstevel@tonic-gatepilotAttributeType 7 : photo 8590Sstevel@tonic-gatepilotAttributeType 8 : : userClass 8600Sstevel@tonic-gatepilotAttributeType 9 : host 8610Sstevel@tonic-gatepilotAttributeType 10 : manager 8620Sstevel@tonic-gatepilotAttributeType 11 : : documentIdentifier 8630Sstevel@tonic-gatepilotAttributeType 12 : : documentTitle 8640Sstevel@tonic-gatepilotAttributeType 13 : : documentVersion 8650Sstevel@tonic-gatepilotAttributeType 14 : : documentAuthor 8660Sstevel@tonic-gatepilotAttributeType 15 : : documentLocation 8670Sstevel@tonic-gatepilotAttributeType 20 : : homeTelephoneNumber 8680Sstevel@tonic-gatepilotAttributeType 21 : secretary 8690Sstevel@tonic-gatepilotAttributeType 22 : : otherMailbox 8700Sstevel@tonic-gatepilotAttributeType 23 : : lastModifiedTime 8710Sstevel@tonic-gatepilotAttributeType 24 : : lastModifiedBy 8720Sstevel@tonic-gatepilotAttributeType 25 : DC : domainComponent 8730Sstevel@tonic-gatepilotAttributeType 26 : : aRecord 8740Sstevel@tonic-gatepilotAttributeType 27 : : pilotAttributeType27 8750Sstevel@tonic-gatepilotAttributeType 28 : : mXRecord 8760Sstevel@tonic-gatepilotAttributeType 29 : : nSRecord 8770Sstevel@tonic-gatepilotAttributeType 30 : : sOARecord 8780Sstevel@tonic-gatepilotAttributeType 31 : : cNAMERecord 8790Sstevel@tonic-gatepilotAttributeType 37 : : associatedDomain 8800Sstevel@tonic-gatepilotAttributeType 38 : : associatedName 8810Sstevel@tonic-gatepilotAttributeType 39 : : homePostalAddress 8820Sstevel@tonic-gatepilotAttributeType 40 : : personalTitle 8830Sstevel@tonic-gatepilotAttributeType 41 : : mobileTelephoneNumber 8840Sstevel@tonic-gatepilotAttributeType 42 : : pagerTelephoneNumber 8850Sstevel@tonic-gatepilotAttributeType 43 : : friendlyCountryName 8860Sstevel@tonic-gate# The following clashes with 2.5.4.45, so commented away 8870Sstevel@tonic-gate#pilotAttributeType 44 : uid : uniqueIdentifier 8880Sstevel@tonic-gatepilotAttributeType 45 : : organizationalStatus 8890Sstevel@tonic-gatepilotAttributeType 46 : : janetMailbox 8900Sstevel@tonic-gatepilotAttributeType 47 : : mailPreferenceOption 8910Sstevel@tonic-gatepilotAttributeType 48 : : buildingName 8920Sstevel@tonic-gatepilotAttributeType 49 : : dSAQuality 8930Sstevel@tonic-gatepilotAttributeType 50 : : singleLevelQuality 8940Sstevel@tonic-gatepilotAttributeType 51 : : subtreeMinimumQuality 8950Sstevel@tonic-gatepilotAttributeType 52 : : subtreeMaximumQuality 8960Sstevel@tonic-gatepilotAttributeType 53 : : personalSignature 8970Sstevel@tonic-gatepilotAttributeType 54 : : dITRedirect 8980Sstevel@tonic-gatepilotAttributeType 55 : audio 8990Sstevel@tonic-gatepilotAttributeType 56 : : documentPublisher 9000Sstevel@tonic-gate 901*2139Sjp161948international-organizations 42 : id-set : Secure Electronic Transactions 9020Sstevel@tonic-gate 9030Sstevel@tonic-gateid-set 0 : set-ctype : content types 9040Sstevel@tonic-gateid-set 1 : set-msgExt : message extensions 9050Sstevel@tonic-gateid-set 3 : set-attr 9060Sstevel@tonic-gateid-set 5 : set-policy 9070Sstevel@tonic-gateid-set 7 : set-certExt : certificate extensions 9080Sstevel@tonic-gateid-set 8 : set-brand 9090Sstevel@tonic-gate 9100Sstevel@tonic-gateset-ctype 0 : setct-PANData 9110Sstevel@tonic-gateset-ctype 1 : setct-PANToken 9120Sstevel@tonic-gateset-ctype 2 : setct-PANOnly 9130Sstevel@tonic-gateset-ctype 3 : setct-OIData 9140Sstevel@tonic-gateset-ctype 4 : setct-PI 9150Sstevel@tonic-gateset-ctype 5 : setct-PIData 9160Sstevel@tonic-gateset-ctype 6 : setct-PIDataUnsigned 9170Sstevel@tonic-gateset-ctype 7 : setct-HODInput 9180Sstevel@tonic-gateset-ctype 8 : setct-AuthResBaggage 9190Sstevel@tonic-gateset-ctype 9 : setct-AuthRevReqBaggage 9200Sstevel@tonic-gateset-ctype 10 : setct-AuthRevResBaggage 9210Sstevel@tonic-gateset-ctype 11 : setct-CapTokenSeq 9220Sstevel@tonic-gateset-ctype 12 : setct-PInitResData 9230Sstevel@tonic-gateset-ctype 13 : setct-PI-TBS 9240Sstevel@tonic-gateset-ctype 14 : setct-PResData 9250Sstevel@tonic-gateset-ctype 16 : setct-AuthReqTBS 9260Sstevel@tonic-gateset-ctype 17 : setct-AuthResTBS 9270Sstevel@tonic-gateset-ctype 18 : setct-AuthResTBSX 9280Sstevel@tonic-gateset-ctype 19 : setct-AuthTokenTBS 9290Sstevel@tonic-gateset-ctype 20 : setct-CapTokenData 9300Sstevel@tonic-gateset-ctype 21 : setct-CapTokenTBS 9310Sstevel@tonic-gateset-ctype 22 : setct-AcqCardCodeMsg 9320Sstevel@tonic-gateset-ctype 23 : setct-AuthRevReqTBS 9330Sstevel@tonic-gateset-ctype 24 : setct-AuthRevResData 9340Sstevel@tonic-gateset-ctype 25 : setct-AuthRevResTBS 9350Sstevel@tonic-gateset-ctype 26 : setct-CapReqTBS 9360Sstevel@tonic-gateset-ctype 27 : setct-CapReqTBSX 9370Sstevel@tonic-gateset-ctype 28 : setct-CapResData 9380Sstevel@tonic-gateset-ctype 29 : setct-CapRevReqTBS 9390Sstevel@tonic-gateset-ctype 30 : setct-CapRevReqTBSX 9400Sstevel@tonic-gateset-ctype 31 : setct-CapRevResData 9410Sstevel@tonic-gateset-ctype 32 : setct-CredReqTBS 9420Sstevel@tonic-gateset-ctype 33 : setct-CredReqTBSX 9430Sstevel@tonic-gateset-ctype 34 : setct-CredResData 9440Sstevel@tonic-gateset-ctype 35 : setct-CredRevReqTBS 9450Sstevel@tonic-gateset-ctype 36 : setct-CredRevReqTBSX 9460Sstevel@tonic-gateset-ctype 37 : setct-CredRevResData 9470Sstevel@tonic-gateset-ctype 38 : setct-PCertReqData 9480Sstevel@tonic-gateset-ctype 39 : setct-PCertResTBS 9490Sstevel@tonic-gateset-ctype 40 : setct-BatchAdminReqData 9500Sstevel@tonic-gateset-ctype 41 : setct-BatchAdminResData 9510Sstevel@tonic-gateset-ctype 42 : setct-CardCInitResTBS 9520Sstevel@tonic-gateset-ctype 43 : setct-MeAqCInitResTBS 9530Sstevel@tonic-gateset-ctype 44 : setct-RegFormResTBS 9540Sstevel@tonic-gateset-ctype 45 : setct-CertReqData 9550Sstevel@tonic-gateset-ctype 46 : setct-CertReqTBS 9560Sstevel@tonic-gateset-ctype 47 : setct-CertResData 9570Sstevel@tonic-gateset-ctype 48 : setct-CertInqReqTBS 9580Sstevel@tonic-gateset-ctype 49 : setct-ErrorTBS 9590Sstevel@tonic-gateset-ctype 50 : setct-PIDualSignedTBE 9600Sstevel@tonic-gateset-ctype 51 : setct-PIUnsignedTBE 9610Sstevel@tonic-gateset-ctype 52 : setct-AuthReqTBE 9620Sstevel@tonic-gateset-ctype 53 : setct-AuthResTBE 9630Sstevel@tonic-gateset-ctype 54 : setct-AuthResTBEX 9640Sstevel@tonic-gateset-ctype 55 : setct-AuthTokenTBE 9650Sstevel@tonic-gateset-ctype 56 : setct-CapTokenTBE 9660Sstevel@tonic-gateset-ctype 57 : setct-CapTokenTBEX 9670Sstevel@tonic-gateset-ctype 58 : setct-AcqCardCodeMsgTBE 9680Sstevel@tonic-gateset-ctype 59 : setct-AuthRevReqTBE 9690Sstevel@tonic-gateset-ctype 60 : setct-AuthRevResTBE 9700Sstevel@tonic-gateset-ctype 61 : setct-AuthRevResTBEB 9710Sstevel@tonic-gateset-ctype 62 : setct-CapReqTBE 9720Sstevel@tonic-gateset-ctype 63 : setct-CapReqTBEX 9730Sstevel@tonic-gateset-ctype 64 : setct-CapResTBE 9740Sstevel@tonic-gateset-ctype 65 : setct-CapRevReqTBE 9750Sstevel@tonic-gateset-ctype 66 : setct-CapRevReqTBEX 9760Sstevel@tonic-gateset-ctype 67 : setct-CapRevResTBE 9770Sstevel@tonic-gateset-ctype 68 : setct-CredReqTBE 9780Sstevel@tonic-gateset-ctype 69 : setct-CredReqTBEX 9790Sstevel@tonic-gateset-ctype 70 : setct-CredResTBE 9800Sstevel@tonic-gateset-ctype 71 : setct-CredRevReqTBE 9810Sstevel@tonic-gateset-ctype 72 : setct-CredRevReqTBEX 9820Sstevel@tonic-gateset-ctype 73 : setct-CredRevResTBE 9830Sstevel@tonic-gateset-ctype 74 : setct-BatchAdminReqTBE 9840Sstevel@tonic-gateset-ctype 75 : setct-BatchAdminResTBE 9850Sstevel@tonic-gateset-ctype 76 : setct-RegFormReqTBE 9860Sstevel@tonic-gateset-ctype 77 : setct-CertReqTBE 9870Sstevel@tonic-gateset-ctype 78 : setct-CertReqTBEX 9880Sstevel@tonic-gateset-ctype 79 : setct-CertResTBE 9890Sstevel@tonic-gateset-ctype 80 : setct-CRLNotificationTBS 9900Sstevel@tonic-gateset-ctype 81 : setct-CRLNotificationResTBS 9910Sstevel@tonic-gateset-ctype 82 : setct-BCIDistributionTBS 9920Sstevel@tonic-gate 9930Sstevel@tonic-gateset-msgExt 1 : setext-genCrypt : generic cryptogram 9940Sstevel@tonic-gateset-msgExt 3 : setext-miAuth : merchant initiated auth 9950Sstevel@tonic-gateset-msgExt 4 : setext-pinSecure 9960Sstevel@tonic-gateset-msgExt 5 : setext-pinAny 9970Sstevel@tonic-gateset-msgExt 7 : setext-track2 9980Sstevel@tonic-gateset-msgExt 8 : setext-cv : additional verification 9990Sstevel@tonic-gate 10000Sstevel@tonic-gateset-policy 0 : set-policy-root 10010Sstevel@tonic-gate 10020Sstevel@tonic-gateset-certExt 0 : setCext-hashedRoot 10030Sstevel@tonic-gateset-certExt 1 : setCext-certType 10040Sstevel@tonic-gateset-certExt 2 : setCext-merchData 10050Sstevel@tonic-gateset-certExt 3 : setCext-cCertRequired 10060Sstevel@tonic-gateset-certExt 4 : setCext-tunneling 10070Sstevel@tonic-gateset-certExt 5 : setCext-setExt 10080Sstevel@tonic-gateset-certExt 6 : setCext-setQualf 10090Sstevel@tonic-gateset-certExt 7 : setCext-PGWYcapabilities 10100Sstevel@tonic-gateset-certExt 8 : setCext-TokenIdentifier 10110Sstevel@tonic-gateset-certExt 9 : setCext-Track2Data 10120Sstevel@tonic-gateset-certExt 10 : setCext-TokenType 10130Sstevel@tonic-gateset-certExt 11 : setCext-IssuerCapabilities 10140Sstevel@tonic-gate 10150Sstevel@tonic-gateset-attr 0 : setAttr-Cert 10160Sstevel@tonic-gateset-attr 1 : setAttr-PGWYcap : payment gateway capabilities 10170Sstevel@tonic-gateset-attr 2 : setAttr-TokenType 10180Sstevel@tonic-gateset-attr 3 : setAttr-IssCap : issuer capabilities 10190Sstevel@tonic-gate 10200Sstevel@tonic-gatesetAttr-Cert 0 : set-rootKeyThumb 10210Sstevel@tonic-gatesetAttr-Cert 1 : set-addPolicy 10220Sstevel@tonic-gate 10230Sstevel@tonic-gatesetAttr-TokenType 1 : setAttr-Token-EMV 10240Sstevel@tonic-gatesetAttr-TokenType 2 : setAttr-Token-B0Prime 10250Sstevel@tonic-gate 10260Sstevel@tonic-gatesetAttr-IssCap 3 : setAttr-IssCap-CVM 10270Sstevel@tonic-gatesetAttr-IssCap 4 : setAttr-IssCap-T2 10280Sstevel@tonic-gatesetAttr-IssCap 5 : setAttr-IssCap-Sig 10290Sstevel@tonic-gate 10300Sstevel@tonic-gatesetAttr-IssCap-CVM 1 : setAttr-GenCryptgrm : generate cryptogram 10310Sstevel@tonic-gatesetAttr-IssCap-T2 1 : setAttr-T2Enc : encrypted track 2 10320Sstevel@tonic-gatesetAttr-IssCap-T2 2 : setAttr-T2cleartxt : cleartext track 2 10330Sstevel@tonic-gate 10340Sstevel@tonic-gatesetAttr-IssCap-Sig 1 : setAttr-TokICCsig : ICC or token signature 10350Sstevel@tonic-gatesetAttr-IssCap-Sig 2 : setAttr-SecDevSig : secure device signature 10360Sstevel@tonic-gate 10370Sstevel@tonic-gateset-brand 1 : set-brand-IATA-ATA 10380Sstevel@tonic-gateset-brand 30 : set-brand-Diners 10390Sstevel@tonic-gateset-brand 34 : set-brand-AmericanExpress 10400Sstevel@tonic-gateset-brand 35 : set-brand-JCB 10410Sstevel@tonic-gateset-brand 4 : set-brand-Visa 10420Sstevel@tonic-gateset-brand 5 : set-brand-MasterCard 10430Sstevel@tonic-gateset-brand 6011 : set-brand-Novus 10440Sstevel@tonic-gate 10450Sstevel@tonic-gatersadsi 3 10 : DES-CDMF : des-cdmf 10460Sstevel@tonic-gatersadsi 1 1 6 : rsaOAEPEncryptionSET 1047*2139Sjp161948 1048*2139Sjp161948 : Oakley-EC2N-3 : ipsec3 1049*2139Sjp161948 : Oakley-EC2N-4 : ipsec4 1050