Skip to main content

Certificate template structure

A certificate template defines the structure, constraints, and behaviors of certificates issued through a certificate profile and a certificate management policy. The template body is defined using JSON, and controls certificate content, cryptographic settings, validation rules, and lifecycle behavior.

Device Trust Manager supports the following template formats:

  • X.509: The International Telecommunication Union (ITU) standard format of public key certificates. It supports RSA and ECDSA certificates

  • Global platform: These certificates are around one-tenth the size of an X.509 certificate. It supports ECDSA certificates only

  • Attribute certificate: An RFC 5755 certificate that assigns authorization attributes to an existing holder; it does not bind a new public key

表 1. Supported components by template type

Component

Purpose

X.509

Global Platform

Attribute certificate

Signature algorithms

Defines the allowed signature algorithms that can be used to sign certificate requests

✅

✅

✅

Key types

Defines the supported key types that can be used in issued certificates

✅

❌

❌

Subject attributes

Defines the subject information included in the certificate

✅

✅

❌

Extensions

Defines certificate extensions and their values

✅

✅

✅

Renewal settings

Defines the conditions and rules for certificate renewal

✅

✅

✅

Subject key identifier method

Defines how the Subject Key Identifier (SKI) is generated

✅

❌

❌

Serial number size

Defines the size of generated certificate serial numbers

✅

❌

❌

Validity

Defines the certificate validity period or expiration date

✅

✅

✅

Certificate size check settings

Defines certificate size limits and validation rules

✅

✅

✅

Custom attributes

Defines additional metadata that is not included in the issued certificate

✅

❌

❌

Certificate type

Defines the type of Global Platform certificate to issue

❌

✅

❌

Version

Defines the attribute certificate version

❌

❌

✅

Holder source

Defines the source used to identify the certificate holder

❌

❌

✅

Attributes

Defines the authorization and identity attributes included in the attribute certificate

❌

❌

✅


Example template structure

{
  "signatureAlgorithms": {},
  "keyTypes": {},
  "subjectAttributes": {},
  "extensions": {},
  "renewalSettings": {},
  "subjectKeyIdentifierMethod": {},
  "serialNumberSize": {},
  "validity": {},
  "certificateSizeCheckSettings": {},
  "customAttributes": {}
}
`