Skip to main content

Certificate template structure

A certificate template defines the structure, constraints, and behaviors of certificates issued through a certificate profile and a certificate management policy. The template body is defined using JSON, and controls certificate content, cryptographic settings, validation rules, and lifecycle behavior.

Device Trust Manager supports the following template formats:

  • X.509: The International Telecommunication Union (ITU) standard format of public key certificates. It supports RSA and ECDSA certificates

  • Global platform: These certificates are around one-tenth the size of an X.509 certificate. It supports ECDSA certificates only

  • Attribute certificate: An RFC 5755 certificate that assigns authorization attributes to an existing holder; it does not bind a new public key

Tabella 1. Supported components by template type

Component

Purpose

X.509

Global Platform

Attribute certificate

Signature algorithms

Defines the allowed signature algorithms that can be used to sign certificate requests

✅

✅

✅

Key types

Defines the supported key types that can be used in issued certificates

✅

❌

❌

Subject attributes

Defines the subject information included in the certificate

✅

✅

❌

Extensions

Defines certificate extensions and their values

✅

✅

✅

Renewal settings

Defines the conditions and rules for certificate renewal

✅

✅

✅

Subject key identifier method

Defines how the Subject Key Identifier (SKI) is generated

✅

❌

❌

Serial number size

Defines the size of generated certificate serial numbers

✅

❌

❌

Validity

Defines the certificate validity period or expiration date

✅

✅

✅

Certificate size check settings

Defines certificate size limits and validation rules

✅

✅

✅

Custom attributes

Defines additional metadata that is not included in the issued certificate

✅

❌

❌

Certificate type

Defines the type of Global Platform certificate to issue

❌

✅

❌

Version

Defines the attribute certificate version

❌

❌

✅

Holder source

Defines the source used to identify the certificate holder

❌

❌

✅

Attributes

Defines the authorization and identity attributes included in the attribute certificate

❌

❌

✅


Example template structure

{
  "signatureAlgorithms": {},
  "keyTypes": {},
  "subjectAttributes": {},
  "extensions": {},
  "renewalSettings": {},
  "subjectKeyIdentifierMethod": {},
  "serialNumberSize": {},
  "validity": {},
  "certificateSizeCheckSettings": {},
  "customAttributes": {}
}
`