--
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe@openssl.org.
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aYFWle5JFb_2ckFp%40chardros.imrryr.org.
On Mon, Feb 02, 2026 at 10:05:53PM -0800, SIMON BABY wrote:Is this valid for root CA and intermediate CA certificate also ? Or only valid for user certificate? . I am trying to understand if there is any security concerns when there is no extensions in the certificate ?Depends on what you mean by "this"? :-) - CA certificates generally don't need or have EKU extensions. If they do have an EKU extension, then (rfc5280 notwithstanding) OpenSSL and IIRC some other implementations interpret that extension as an additional limitation on the usage of the EE key. So skip the EKU extension, or also list "clientAuth" if the CA is going to issue TLS client certificates.
- OpenSSL tolerates (implicitly) CA certificates that have neither a basicConstraints nor a keyUsage extension, but this is not recommended.
Yep.
A CA should have at least:
basicConstraints: CA:true, ...
keyUsage: keyCertSign, ...
subjectKeyIdentifiter: ...
authorityKeyIdentifiter: ...
Further extensions that may be helpful to have in all certs (except root / trust anchor) are CDP and AIA entries providing info for revocation checking using CRLs or OCSP, respectively.
David
--
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe@openssl.org.
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aYGjrdyC_2sZjREN%40chardros.imrryr.org.
--
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe@openssl.org.
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aYH-thr8JOTNamra%40chardros.imrryr.org.