C=US Schemas
These are the schemas behind the C=US agent registry: the OpenLDAP schema for agents, grants, certificate bindings and the maple and tart-cherry use cases; the accountable-delegation extension and its JSON Schema; and the one file every enforcement point reads its scope names from. The files below are the same ones in the project repository, published unchanged.
Files
-
cus-registry.schemaOpenLDAP schema
The registry. 14 object classes, including
cequsRegisteredAgent,cequsAuthorizationGrant,cequsCertificateBinding,cequsTrustedIssuer,cequsCertifiedEndorser,cequsRegisteredFarmandcequsSediProofedPerson, plus the maple and tart-cherry records. OID root1.3.6.1.4.1.3609.4, under Cequs Inc.’s IANA Private Enterprise Number 3609. -
The canonical scope identifiers, such as
maple.lot.grade.proposeandmaple.lot.grade.finalize. The registration approver, the mTLS gateway and the delegation engine all read their scope strings from this file, so a rename happens in one place. -
delegation/protocol.v1.schema.jsonJSON Schema 2020-12
The accountable-delegation protocol v1. Agent, grant, deployment, credential, endpoint, request, decision and evidence records are each addressable under
$defs. Unknown fields and versions fail closed. -
delegation/cequs-delegation.schemaOpenLDAP schema
The LDAP side of the delegation protocol: two auxiliary classes (
cequsAccountableAgentV1,cequsBoundedGrantV1) carrying versioned JSON records. Load it aftercus-registry.schema. -
delegation/examples.jsonJSON fixtures
Synthetic delegation examples for the protocol, with UTC validity windows. The keys and fingerprints in it are deliberately nonfunctional placeholders.
-
delegation/examples.ldifLDIF fixtures
The same synthetic agents and grants as LDAP entries.
-
examples/maple-syrup-registry.ldifLDIF fixtures
An illustrative directory tree: one agent, a grove, a portable Raman device, a syrup lot, a measurement, and a bounded authorization grant.
Full documentation, including the certificate-binding acceptance rule and the JSON-to-LDAP mapping table, is in the repository’s schema README and delegation README.
Only a grant authorizes. cequsDeclaredScope on an agent entry is a descriptive label with no time bounds. cequsAuthorizedScope on a cequsAuthorizationGrant, read together with cequsGrantStart and cequsGrantEnd, is the only attribute an evaluator should consult. They were once one attribute, and the unbounded copy bypassed the grant window.
A sponsor claim is not a proofed identity. cequsSponsor records what the registrar asserted. cequsAccountableSponsor is set only after identity proofing, which is not built yet.
LDAP write access is not authorization. Grants, expiry, attestation, revocation and audit are enforced by the service that reads the directory, and it must fail closed.
Loading into a test directory
For a slapd.conf deployment, load the standard schemas first, then the registry, then the delegation extension:
include /etc/ldap/schema/core.schema include /etc/ldap/schema/cosine.schema include /etc/ldap/schema/cus-registry.schema include /etc/ldap/schema/cequs-delegation.schema
Check the configuration with slaptest -f /etc/ldap/slapd.conf -u before starting the server. For a cn=config deployment, convert and load the schemas in a test environment first; don’t hand-edit a live cn=config database.
The certificate-binding and trusted-issuer classes have been rehearsed on a throwaway OpenLDAP 2.6.10 server but are not applied to the live C=US directory. The delegation extension is for an isolated local test directory only. The maple and tart-cherry records are illustrative and establish no grading standard. An Internet Directory Number under 1.3.6.1.1 has been requested; if one is assigned, the OID root line changes.