Skip to main content

SKI extension

The subject key identifier extension allows you to define the subject key identifiers in the certificate.

JSON structure examples

"extensions": {
  "ski_extension": {
    "include": "yes",
    "default_method": "method1",
    "allowed_methods": [
      "method1",
      "method2"
    ]
  }
}
"extensions": {
  "ski_extension": {
    "include": "no"
  }
}

Parameters

tabel 1. Parameters: SKI extension

Name

Type

Required/optional

Possible values

ski_extension

Object

Optional

-

.. include

String

Optional

Specifies whether the Subject Directory Attributes extension is included in issued certificates. Supported values include:

  • yes: Always includes the extension

  • Optional: Includes the extension only when a value is provided

  • no: Excludes the extension

.. default_method

String

Optional

Specifies whether encoded Subject Directory Attribute values can be provided in certificate profiles and enrollment requests. Supported values include:

  • true: Allows encoded extension values

Opmerking

Only true is supported. The value must use the Subject Directory Attribute JSON format

.. allowed_methods

Array of strings

Optional

Enables support for encoded Subject Directory Attribute values. When enabled, certificate profiles and enrollment requests can provide values using the Subject Directory Attribute JSON format