3.4 DN order

Entrust controls the order of the elements of the DN. Your Entrust system may have a different server-side configuration, but by default:

3.4.1 Reversing user DNs

You must align Entrust user DN ordering and MyID DN ordering (where possible) through the use of the Reverse DN setting for each Entrust certificate policy in the CA workflow. A typical user's ordering reflects the CA's own DN ordering.

For example, for a CA whose DN is in the form:

ou=MyEntrustCA,ou=PKI,ou=CA,dc=mydomain,dc=local

Users (known to the CA) would be in the form:

cn=Arthur Alpha,ou=MyEntrustCA,ou=PKI,ou=CA,dc=mydomain,dc=local

However, for PIV issuance, where the form is:

dc=local, dc=mydomain, ou=CA, ou=PKI, ou=MyEntrustCA, cn=Arthur Alpha

Or in the alternative noUserInDirectory case:

C=US, o=U.S. Government, ou=Department of Administration, cn=Arthur Alpha

You must set the Reverse DN flag to true.

Note: MyID does not recognize this option when using the Issue Card workflow to issue a card.