Certificate template structure
A certificate template defines the structure, constraints, and behaviors of certificates issued through a certificate profile and a certificate management policy. The template body is defined using JSON, and controls certificate content, cryptographic settings, validation rules, and lifecycle behavior.
Device Trust Manager supports the following template formats:
X.509: The International Telecommunication Union (ITU) standard format of public key certificates. It supports RSA and ECDSA certificates
Global platform: These certificates are around one-tenth the size of an X.509 certificate. It supports ECDSA certificates only
Attribute certificate: An RFC 5755 certificate that assigns authorization attributes to an existing holder; it does not bind a new public key
Component | Purpose | X.509 | Global Platform | Attribute certificate |
|---|---|---|---|---|
Signature algorithms | Defines the allowed signature algorithms that can be used to sign certificate requests | ✅ | ✅ | ✅ |
Key types | Defines the supported key types that can be used in issued certificates | ✅ | ❌ | ❌ |
Subject attributes | Defines the subject information included in the certificate | ✅ | ✅ | ❌ |
Extensions | Defines certificate extensions and their values | ✅ | ✅ | ✅ |
Renewal settings | Defines the conditions and rules for certificate renewal | ✅ | ✅ | ✅ |
Subject key identifier method | Defines how the Subject Key Identifier (SKI) is generated | ✅ | ❌ | ❌ |
Serial number size | Defines the size of generated certificate serial numbers | ✅ | ❌ | ❌ |
Validity | Defines the certificate validity period or expiration date | ✅ | ✅ | ✅ |
Certificate size check settings | Defines certificate size limits and validation rules | ✅ | ✅ | ✅ |
Custom attributes | Defines additional metadata that is not included in the issued certificate | ✅ | ❌ | ❌ |
Certificate type | Defines the type of Global Platform certificate to issue | ❌ | ✅ | ❌ |
Version | Defines the attribute certificate version | ❌ | ❌ | ✅ |
Holder source | Defines the source used to identify the certificate holder | ❌ | ❌ | ✅ |
Attributes | Defines the authorization and identity attributes included in the attribute certificate | ❌ | ❌ | ✅ |
Example template structure
{
"signatureAlgorithms": {},
"keyTypes": {},
"subjectAttributes": {},
"extensions": {},
"renewalSettings": {},
"subjectKeyIdentifierMethod": {},
"serialNumberSize": {},
"validity": {},
"certificateSizeCheckSettings": {},
"customAttributes": {}
}
`