Previous Topic: Pruning and Replacing Object Classes

Next Topic: Name Bindings

Check Structural Object Classes

By default, CA Directory lets you create an entry with multiple structural object classes that are not part of a single inheritance chain. While this ability can be useful, it does not conform with Section 8.3.2 of X.501 and Section 2.4.2 of RFC 451.

If you do not want entries with multiple unrelated structural object classes to be created, you can use the set check-structural-oc command to enforce this.

If set check-structural-oc is set to true, it will not be possible to add an entry which has more than one structural object class hierarchy.

More information:

set check-structural-oc—Prevent Entries with Multiple Unrelated Structural Object Classes from Being Created