Extended key usage
Extended key usage allows you to define the extended key usage extensions in the certificate.
JSON structure example
"extensions": {
"extended_key_usage": {
"critical": true,
"allow_critical_override": true,
"include": "yes",
"required_usages": [
{
"oid": "client_authentication",
"name": "Client authentication"
},
{
"oid": "server_authentication"
}
],
"optional_usages": [
{
"oid": "code_signing",
"name": "Code signing"
},
{
"oid": "email_protection"
},
{
"oid": "1.2.3.4.567.8.9.0.1",
"name": "Custom OID example"
}
]
}
}
Parameters
Name | Type | Required/optional | Possible values |
|---|---|---|---|
| Object | Required | - |
| Boolean | Optional | Specifies whether the Extended Key Usage extension is marked as critical. Supported values include:
|
| Boolean | Optional |
|
| String | Optional | Specifies whether the Extended Key Usage extension is included in issued certificates. Supported values include:
|
| Array of objects | Optional | - |
| Strings | Required | Specifies the EKU object identifier (OID). You can use a predefined EKU value or provide a custom OID. Supported predefined values include:
|
| String | Required | Specifies an optional display name or description for the EKU |
| Array of objects | Optional | - |
| String | Required | Specifies an Extended Key Usage (EKU) OID that can be included in the issued certificate when allowed by the certificate profile. You can use a predefined EKU value or provide a custom OID.
|
| String | Optional | Specifies an optional display name or description for the EKU |