Skip to main content

Extended key usage

Extended key usage allows you to define the extended key usage extensions in the certificate.

JSON structure example

"extensions": {
  "extended_key_usage": {
    "critical": true,
    "allow_critical_override": true,
    "include": "yes",
    "required_usages": [
      {
        "oid": "client_authentication",
        "name": "Client authentication"
      },
      {
        "oid": "server_authentication"
      }  
    ],
    "optional_usages": [
      {
        "oid": "code_signing",
        "name": "Code signing"
      },
      {
        "oid": "email_protection"
      },
      {
        "oid": "1.2.3.4.567.8.9.0.1",
        "name": "Custom OID example"
      }
    ]
  }
}

Parameters

Tabelle 1. Parameters: Extended key usage

Name

Type

Required/optional

Possible values

extended_key_usage

Object

Required

-

.. critical

Boolean

Optional

Specifies whether the Extended Key Usage extension is marked as critical. Supported values include:

  • true: Marks the extension as critical

  • false: Does not mark the extension as critical

.. allow_critical_override

Boolean

Optional

  • Specifies whether the critical flag can be overridden in a certificate profile or enrollment request. Supported values include:

    • true: Allows the critical flag to be overridden

    • false: Uses the value defined in the certificate template

.. include

String

Optional

Specifies whether the Extended Key Usage extension is included in issued certificates. Supported values include:

  • yes: Includes the extension in the certificate

  • no: Excludes the extension from the certificate

.. required_usages

Array of objects

Optional

-

.. .. oid

Strings

Required

Specifies the EKU object identifier (OID). You can use a predefined EKU value or provide a custom OID. Supported predefined values include:

  • client_authentication

  • server_authentication

  • code_signing

  • email_protection

  • smart_card_logon

  • time_stamping

  • adobe_cds

  • document_signing

  • microsoft_document_signing

  • encrypting_file_system

  • key_purpose_kdc

  • enrollment_agent

  • intel_amt

  • general_document_signing

  • key_recovery_agent

  • bitlocker_drive_encryption

  • bitlocker_data_recovery_agent

.. .. name

String

Required

Specifies an optional display name or description for the EKU

.. optional_usages

Array of objects

Optional

-

.. .. oid

String

Required

Specifies an Extended Key Usage (EKU) OID that can be included in the issued certificate when allowed by the certificate profile. You can use a predefined EKU value or provide a custom OID.

  • client_authentication

  • server_authentication

  • code_signing

  • email_protection

  • smart_card_logon

  • time_stamping

  • adobe_cds

  • document_signing

  • microsoft_document_signing

  • encrypting_file_system

  • key_purpose_kdc

  • enrollment_agent

  • intel_amt

  • general_document_signing

  • key_recovery_agent

  • bitlocker_drive_encryption

  • bitlocker_data_recovery_agent

.. .. .. .. name

String

Optional

Specifies an optional display name or description for the EKU