Skip to main content

Key usage

Defines the Key usage certificate extension.

For Intermediate CA certificate templates that use an unmanaged CA, you can override the default Key usage values configured by the CA manager by setting allow_value_override to true.

Note

The allow_value_override setting has no effect on End Entity certificate templates.

JSON structure example

"extensions": {
  "key_usage": {
    "critical": true,
    "allow_critical_override": true,
    "allow_value_override": true,
    "required_usages": {
      "rsa": [
        "digital_signature"
      ],
      "ecdsa": [
        "digital_signature"
      ],
      "dilithium": [
        "digital_signature"
      ],
      "sphincs": [
        "digital_signature"
      ],
      "falcon": [
        "digital_signature"
      ],
      "composite": [
        "digital_signature"
      ],
      "ml-kem": [
        "key_encipherment"
      ]
    },
    "optional_usages": {
      "rsa": [
        "non_repudiation",
        "key_encipherment",
        "data_encipherment"
      ],
      "ecdsa": [
        "non_repudiation",
        "key_agreement"
      ],
      "dilithium": [
        "non_repudiation"
      ],
      "sphincs": [
        "non_repudiation"
      ],
      "falcon": [
        "non_repudiation"
      ],
      "composite": [
        "non_repudiation"
      ]
    }
  }
}

Parameters

Tableau 1. Parameters: Key usage

Name

Type

Required/optional

Possible values

key_usage

Object

Required

-

.. critical

Boolean

Optional

Specifies whether the Key usage extension is marked as critical. Supported values include:

  • true: Marks the Key usage extension as critical

  • false: Does not mark the Key usage extension as critical

.. allow_critical_override

Boolean

Optional

  • Specifies whether the critical flag can be overridden in a certificate profile or enrollment request. Supported values include:

    • true: Allows the critical flag to be overridden

    • false: Uses the value defined in the certificate template

.. allow_value_override

Boolean

Required ((Intermediate CA templates only)

Specifies whether Key usage values can be overridden for Intermediate CA certificate templates. Supported values include:

  • true: Allows Key usage values to be overridden

  • false: Not supported, and results in an error

.. required_usages

Object

Optional

Specifies the Key usage values that are always included in issued certificates

.. .. rsa

Array of strings

Required

Specifies the required Key usage values for RSA certificates.

  • End-entity:

    • digital_signature

    • non_repudiation

    • key_encipherment

    • data_encipherment

  • Intermediate:

    • digital_signature

    • cert_sign

    • crl_sign

.. .. ecdsa

Array of strings

Required

Specifies the required Key usage values for ECDSA certificates.

  • End-entity:

    • digital_signature

    • non_repudiation

    • key_agreement

    • encipher_only

    • decipher_only

  • Intermediate:

    • digital_signature

    • cert_sign

    • crl_sign

Note

Only one of encipher_only or decipher_only can be specified

.. .. dilithium

Array of strings

Required

Specifies the required Key usage values for MLDSA (Dilithium) certificates

  • End-entity:

    • digital_signature

    • non_repudiation

  • Intermediate:

    • digital_signature

    • cert_sign

    • crl_sign

.. .. sphincs

Array of strings

Required

Specifies the required Key usage values for SLHDSA (SPHINCS+) certificates

  • End-entity:

    • digital_signature

    • non_repudiation

  • Intermediate:

    • digital_signature

    • cert_sign

    • crl_sign

.. .. falcon

Array of strings

Required

Specifies the required Key usage values for FNDSA (Falcon) certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. composite

Array of strings

Required

Specifies the required Key usage values for composite certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. ml-kem

Array of strings

Required

Specifies the required Key usage values for ML-KEM certificates.

End-entity: key_encipherment

Note

ML-KEM certificates must include key_encipherment and must not include digital_signature

.. optional_usages

Object

Optional

Specifies additional Key usage values that can be included when selected in a certificate profile or provided in an enrollment request

.. .. rsa

Array of strings

Required

Specifies the optional Key usage values for RSA certificates. Supported values include:

  • digital_signature

  • non_repudiation

  • key_encipherment

  • data_encipherment

.. .. ecdsa

Array of strings

Required

Specifies the optional Key usage values for ECDSA certificates. Supported values include:

  • digital_signature

  • non_repudiation

  • key_agreement

  • encipher_only

  • decipher_only

Note

Only one of encipher_only or decipher_only can be specified.

.. .. dilithium

Array of strings

Required

Specifies the optional Key usage values for MLDSA (Dilithium) certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. sphincs

Array of strings

Required

Specifies the optional Key Usage values for SLHDSA (SPHINCS+) certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. falcon

Array of strings

Required

Specifies the optional Key Usage values for FNDSA (Falcon) certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. composite

Array of strings

Required

Specifies the optional Key Usage values for composite certificates. Supported values include:

  • digital_signature

  • non_repudiation

.. .. ml-kem

Array of strings

Optional

Optional Key usage values are not supported for ML-KEM certificates. Do not define optional_usages for ML-KEM