A careful code review was undertaken, and it was determined that the best way to store the extended attributes was in a native ASN1 encoded field. LDAP does not understand the SEQUENCE of SEQUENCE structures used extensively throughout the extended attributes structure, and there was already a precedent set for storing the krb5Key data in a native ASN1 encoded field.
		
			
				
	
	
	
		
			50 KiB
		
	
	
	
	
	
	
	
			
		
		
	
	
			50 KiB