Re: openssl x509 certificate question
SIMON BABY <[email protected]> Mon, 2 Feb 2026 22:05:53 -0800
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CAEFUPH0--9o5DoTR_p-D10hcv9XOVBr88LB5BNqa6FMRn+20LA@mail.gmail.com> |
Thank you viktor. Is this valid for root CA and intermediate CA certificate also ? Or only valid for user certificate? . I am trying to understand if there is any security concerns when there is no extensions in the certificate ? Regards Simon On Monday, February 2, 2026, Viktor Dukhovni <[email protected]> wrote: > On Mon, Feb 02, 2026 at 02:13:56PM -0800, SIMON BABY wrote: > > > I would like to know if we can have a client certificate with out any > > extensions in the x509 extensions? Can this function still pass > > through? X509_verify_cert (). > > Yes, that should be fine. The "clientAuth" extended key usage OID is > only required when the EKU extension is present, in its absence the > certiificate is good for all extended key usages. > > Unfortunately, some time back the "openssl req" and "openssl x509" > command-line utilities were changed to automatically add > subjectKeyIdentifier and/or authorityKeyIdentifier extensions. > That really should have been left to the user to decide, but at least > there's an explicit mechanism to ask to turn these off. So, to really > get no extensions, for now you have to ask harder. > > Example, (in practice, you'll avoid the >(...) bash wizardry used with > "-out" and "-keyout"): > > $ openssl req -nodes -x509 -new -newkey ed25519 \ > -keyout >(openssl pkey -noout -text) \ > -config <(printf "[exts]\nsubjectKeyIdentifier = none\n") \ > -subj "/CN=ClientName" -extensions exts \ > -not_after 99991231235959Z \ > -out >(openssl x509 -noout -text) \ > 2>/dev/null | cat > ED25519 Private-Key: > priv: > 18:ef:53:84:10:01:ed:ee:df:27:67:03:c6:0f:b4: > 02:b5:60:bd:7b:69:8e:0e:97:00:0a:53:65:6b:f5: > e1:cb > pub: > 69:99:7d:2b:17:44:26:00:7d:37:7b:80:c5:e5:e6: > cd:b5:a2:ad:c0:dc:ea:22:16:90:a9:54:a1:82:77: > 5c:7b > Certificate: > Data: > Version: 3 (0x2) > Serial Number: > 47:73:10:46:b0:b0:ca:cd:3a:84: > 92:0b:a5:0b:7d:1e:fe:43:e9:1a > Signature Algorithm: ED25519 > Issuer: CN=ClientName > Validity > Not Before: Feb 3 01:57:09 2026 GMT > Not After : Dec 31 23:59:59 9999 GMT > Subject: CN=ClientName > Subject Public Key Info: > Public Key Algorithm: ED25519 > ED25519 Public-Key: > pub: > 69:99:7d:2b:17:44:26:00:7d:37:7b:80:c5:e5:e6: > cd:b5:a2:ad:c0:dc:ea:22:16:90:a9:54:a1:82:77: > 5c:7b > Signature Algorithm: ED25519 > Signature Value: > 12:e6:fe:c3:ae:f0:67:50:9c:04:9e:fd:0f:da:0a:c5:a1:b5: > f3:a7:5d:8b:1f:f3:d2:a9:5d:95:80:c3:c3:33:ca:8d:14:75: > 2a:ad:22:76:85:9e:b9:ce:57:8a:2d:8e:2a:80:bf:db:dd:68: > 4c:5d:3b:48:15:e8:d2:ec:9d:09 > > -- > Viktor. 🇺🇦 Слава Україні! > > -- > You received this message because you are subscribed to the Google Groups > "openssl-users" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org > To view this discussion visit https://groups.google.com/a/ > openssl.org/d/msgid/openssl-users/aYFWle5JFb_2ckFp%40chardros.imrryr.org. > -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAEFUPH0--9o5DoTR_p-D10hcv9XOVBr88LB5BNqa6FMRn%2B20LA%40mail.gmail.com.