Skip to main content

Create a certificate template

A certificate template defines the key parameters and constraints for certificates issued within a certificate management policy. It establishes essential settings such as allowed key types, signature algorithms, and the fields included in the certificate.

Certificate templates standardize the attributes of certificates issued to devices by defining core elements that must be present in each certificate. This consistency ensures that certificates meet technical, security, and regulatory requirements.

Before you begin

Before creating certificate templates, understand the following:

  • You must have a user role that contains the Solution administrator permission.

  • You need a JSON-formatted certificate template prepared.

To create a certificate template:

  1. In the Device Trust Manager menu, go to Certificate management > Certificate settings > Certificate templates.

  2. Click Create > Create certificate template.

  3. Enter a Name for the Certificate template.

  4. Under the Certificate template type, select either End entity or Intermediate CA, depending on your requirement.

  5. In the Format dropdown, select the format for the certificates you want to issue from this template:

    X.509:

    • Supports RSA and ECDSA certificates

    • X.509 is the International Telecommunication Union (ITU) standard format of public key certificates

    Global platform:

    • Supports ECDSA certificates only

    • These certificates are around 1/10 the size of an x509v3 certificate

    Attribute certificate:

    • Binds authorization attributes (such as roles or permissions) to an identity, rather than binding a public key

    • Used primarily for authorization and access control

  6. In the Template body, add your JSON-formatted certificate template information.

    Example JSON certificate template:

    The following example shows a JSON structure of a certificate template.

    {
      "key_gen": {
        "enabled": true,
        "key_type": {
          "allowed_types": [
            "ecdsa"
          ],
          "default_key_type": "ecdsa"
        },
        "ecdsa_curve": {
          "allowed_curves": [
            "P-256",
            "P-384",
            "P-521"
          ],
          "default_curve": "P-256"
        }
      },
      "issue_types": [
        "client_authentication"
      ],
      "signature_algorithm": {
        "allowed_algorithms": [
          "sha256WithECDSA",
          "sha384WithECDSA",
          "sha512WithECDSA",
          "match_issuer"
        ],
        "default_algorithm": "match_issuer"
      },
      "subject": {
        "attributes": [
          {
            "type": "common_name",
            "include": "optional",
            "encoding": "auto",
            "allowed_source": [
              "csr",
              "fixed_value",
              "user_supplied"
            ]
          }
        ]
      },
      "extensions": {
        "key_usage": {
          "critical": true,
          "required_usages": {
            "rsa": [
              "digital_signature",
              "key_encipherment"
            ],
            "ecdsa": [
              "digital_signature"
            ]
          },
          "optional_usages": {
            "rsa": [
              "data_encipherment"
            ],
            "ecdsa": [
              "key_agreement"
            ]
          }
        },
        "extended_key_usage": {
          "critical": true,
          "include": "optional",
          "required_usages": [
            {
              "oid": "client_authentication",
              "name": "Client Authentication"
            }
          ]
        }
      },
      "serial_number_size": 20,
      "validity": {
        "min_duration": {
          "value": 1,
          "unit": "DAYS"
        },
        "max_duration": {
          "value": 10,
          "unit": "YEARS"
        },
        "default_duration": {
          "value": 10,
          "unit": "YEARS"
        }
      }
    }
  7. In the Limited accounts dropdown, select the accounts that can use this template.

  8. When ready, select:

    • Create: Creates the certificate template

      The completed certificate template is listed under Certificate management > Certificate settings > Certificate templates

    • Create and select: Create the certificate template and proceed to the Certificate profile creation section.