Skip to main content

Basic constraints

The basic constraints parameter allows you to define the basic constraints extensions.

JSON structure example

"extensions": {
  "basic_constraints": {
    "include": "yes",
    "ca": true
    "path_length": 2
  }
}
"extensions": {
  "basic_constraints": {
    "include": "no"
  }
}

Parameters

tabla 1. Parameters: Basic constraints

Name

Type

Required/optional

Possible values

basic_constraints

Object

Optional

-

.. include

String

Optional

Specifies whether the Basic Constraints extension is included in issued certificates. Supported values include:

  • yes: Includes the Basic Constraints extension

  • no: Excludes the Basic Constraints extension

.. ca

Boolean

Optional

Specifies whether the certificate can act as a Certification Authority (CA). Supported values include:

  • true: Marks the certificate as a CA certificate

  • false: Marks the certificate as an end-entity certificate

Nota

To set this value to true, the issuing CA must be a private issuer and must support issuing CA certificates. When ca is set to true, the required Key usage values are applied automatically. Any conflicting Key usage configuration in the template causes template validation to fail.

.. path_length

Integer

Optional

Specifies the maximum number of subordinate CA certificates that can exist below this CA in the certification path. Supported values include:

  • -1: Excludes the pathLenConstraint field from the certificate

  • 0: Does not allow subordinate CA certificates

  • >0: Sets the maximum allowed certification path length

Nota

This setting is ignored when ca is false.

critical

Boolean

Optional

Specifies whether the Basic Constraints extension is marked as critical. Supported values include:

  • true: Marks the extension as critical

  • false: Does not mark the extension as critical