Skip to main content

Certificate policies

Certificate policies allow you to define the certificate policy extensions in the certificate.

JSON structure example

"extensions": {
  "certificate_policies": {
    "critical": false,
    "include": "yes",
    "source": [
        "request",
        "template"
    ],
    "value": [
      {
        "oid":"1.2.4.5",
        "cps_uri":"https://www.digicert.com/cps",
        "user_notice":"Legal notice"
      }, {
        "oid":"1.2.615.4"
      }
    ],
	"required":
	[
	  {
		"oid":"2.23.140.1.2.2"
	  }, {
		"oid":"2.23.140.1.2.3"
	  }, {
		"oid":"2.23.140.1.1"
	  }, {
		"oid":"2.23.140.1.2.1"
	  }
	],
	"optional":
	[
	  {
		"oid":"2.23.140.1.2.200"
	  }, {
		"oid":"2.23.140.1.2.201"
	  }
    ]
  }
}

Parameters

Tabelle 1. Parameters: Certificate policies

Name

Type

Required/optional

Possible values

certificate_policies

Object

Optional

-

.. critical

Boolean

Optional

Specifies whether the Certificate Policies extension is marked as critical. Supported values include:

  • true: Marks the extension as critical

  • false: Does not mark the extension as critical

.. include

String

Optional

Specifies whether the Certificate Policies extension is included in issued certificates. Supported values include:

  • yes: Always includes the extension

  • optional: Includes the extension only when values are provided

  • no: Excludes the extension

  • default: Uses the include setting configured on the issuing CA certificate

.. source

Array of strings

Optional

Specifies the allowed sources for certificate policy values. If multiple sources are configured and contain values, the source with the highest priority is used. Supported values include (highest to lowest priority):

  • request: Uses values provided in the certificate request

  • template: Uses values defined in the certificate template

  • issuer: Copies values from the issuer certificate

  • ca_config: Uses values defined in the issuing CA configuration

.. value

Object

Optional

Specifies certificate policy values that can be included when template is configured as a source.

.. .. oid

String

Required

Specifies the certificate policy OID

.. .. cps_uri

String

Optional

Specifies the URI of the Certification Practice Statement (CPS)

.. .. user_notice

String

Optional

Specifies a user notice associated with the certificate policy

.. required

Object

Optional

Specifies certificate policy values that are always included in issued certificates, regardless of the configured source

.. .. oid

String

Required

Specifies the certificate policy OID

.. .. cps_uri

String

Optional

Specifies the URI of the Certification Practice Statement (CPS)

.. .. user_notice

String

Optional

Specifies a user notice associated with the certificate policy

.. optional

Object

Optional

  • Specifies certificate policy values that can be requested when request is configured as a source

  • If this list is empty, any policy OID can be provided in the certificate request. If this list contains entries, only the listed policy OIDs can be requested

  • When a policy is selected, the CPS URI and user notice values are taken from the template configuration rather than the certificate request

.. .. cps_uri

String

Optional

Specifies the URI of the Certification Practice Statement (CPS) associated with the policy

.. .. user_notice

String

Optional

Specifies a user notice associated with the certificate policy