Re: openssl x509 certificate question
SIMON BABY <[email protected]> Tue, 3 Feb 2026 03:04:20 -0800
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CAEFUPH0h6EHK12aRTdc0_rb1ckXJvZLDANjM_d9vMzYDdyB2Fg@mail.gmail.com> |
Thank you for the clarification . Yes I was asking about the case where all
the extensions are empty in root CA and intermediate CA as well.
So in your example what happen if the below fields are also empty ?
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Subject Key Identifier:
5A:8C:87:49:BF:97:DC:64:30:53:
2B:49:F1:0D:57:45:70:FF:EA:92
X509v3 Authority Key Identifier:
D9:D8:10:05:D5:E2:82:20:98:79:
8A:57:B6:76:5D:43:0D:54:86:AE
Do we have any RFC saying about the mandatory and optional extensions in
CA’s and user certs ?
Regards
Simon
On Monday, February 2, 2026, Viktor Dukhovni <[email protected]>
wrote:
> On Mon, Feb 02, 2026 at 10:05:53PM -0800, SIMON BABY wrote:
>
> > Is this valid for root CA and intermediate CA certificate also ? Or only
> > valid for user certificate? . I am trying to understand if there is any
> > security concerns when there is no extensions in the certificate ?
>
> Depends on what you mean by "this"? :-)
>
> - CA certificates generally don't need or have EKU extensions. If they
> do have an EKU extension, then (rfc5280 notwithstanding) OpenSSL and
> IIRC some other implementations interpret that extension as an
> additional limitation on the usage of the EE key. So skip the EKU
> extension, or also list "clientAuth" if the CA is going to issue TLS
> client certificates.
>
> - OpenSSL tolerates (implicitly) CA certificates that have neither a
> basicConstraints nor a keyUsage extension, but this is not
> recommended. A CA should have at least:
>
> basicConstraints: CA:true, ...
> keyUsage: keyCertSign, ...
> subjectKeyIdentifiter: ...
> authorityKeyIdentifiter: ...
>
> To generate a root CA (generally protect with a strong password,
> rather use "-nodes" to disable encryption):
>
> $ openssl req -quiet -nodes -new \
> -keyout rootkey.pem -newkey rsa:2048 \
> -x509 -out rootcrt.pem \
> -subj "/CN=Root CA" -not_after 99991231235959Z \
> -addext "basicConstraints = critical, CA:true" \
> -addext "keyUsage = critical, cRLSign, keyCertSign"\
> -addext "subjectKeyIdentifier = hash" \
> -addext "authorityKeyIdentifier = keyid:always"
> $ openssl x509 -in rootcrt.pem -noout -text -certopt
> no_pubkey,no_sigdump
> Certificate:
> Data:
> Version: 3 (0x2)
> Serial Number:
> 7c:ed:8d:cd:6a:1c:c9:ad:ee:c2:
> 16:9d:6e:73:1c:b3:d4:e8:dd:2d
> Signature Algorithm: sha256WithRSAEncryption
> Issuer: CN=Root CA
> Validity
> Not Before: Feb 3 07:12:25 2026 GMT
> Not After : Dec 31 23:59:59 9999 GMT
> Subject: CN=Root CA
> X509v3 extensions:
> X509v3 Basic Constraints: critical
> CA:TRUE
> X509v3 Key Usage: critical
> Certificate Sign, CRL Sign
> X509v3 Subject Key Identifier:
> D9:D8:10:05:D5:E2:82:20:98:79:
> 8A:57:B6:76:5D:43:0D:54:86:AE
> X509v3 Authority Key Identifier:
> D9:D8:10:05:D5:E2:82:20:98:79:
> 8A:57:B6:76:5D:43:0D:54:86:AE
>
> An intermediate might then be generated as follows:
>
> $ openssl req -quiet -nodes -new \
> -keyout cakey.pem -newkey rsa:2048 \
> -x509 -out cacrt.pem \
> -subj "/CN=Issuer CA" -days 7305 \
> -CAkey rootkey.pem -CA rootcrt.pem \
> -addext "basicConstraints = critical, CA:true, pathlen:0" \
> -addext "keyUsage = critical, cRLSign, keyCertSign"\
> -addext "subjectKeyIdentifier = hash" \
> -addext "authorityKeyIdentifier = keyid:always"
> $ openssl x509 -in cacrt.pem -noout -text -certopt no_pubkey,no_sigdump
> Certificate:
> Data:
> Version: 3 (0x2)
> Serial Number:
> 6b:dc:1b:4a:a3:23:d3:89:a7:e4:
> 0e:2e:76:0a:a6:07:60:78:33:1e
> Signature Algorithm: sha256WithRSAEncryption
> Issuer: CN=Root CA
> Validity
> Not Before: Feb 3 07:21:02 2026 GMT
> Not After : Feb 3 07:21:02 2046 GMT
> Subject: CN=Issuer CA
> X509v3 extensions:
> X509v3 Basic Constraints: critical
> CA:TRUE, pathlen:0
> X509v3 Key Usage: critical
> Certificate Sign, CRL Sign
> X509v3 Subject Key Identifier:
> 5A:8C:87:49:BF:97:DC:64:30:53:
> 2B:49:F1:0D:57:45:70:FF:EA:92
> X509v3 Authority Key Identifier:
> D9:D8:10:05:D5:E2:82:20:98:79:
> 8A:57:B6:76:5D:43:0D:54:86:AE
>
> You might find the Webinar helpful:
>
> - Slides: https://docs.google.com/presentation/d/1xU2-U_
> 6uUW4gB3j_v7EQC81t1RZ_slHyY_91MLlMDEg/edit?slide=id.
> g2b4be0ee06d_0_0#slide=id.g2b4be0ee06d_0_0
> - Video : https://www.youtube.com/watch?v=OuH4vwmzP_o
>
> --
> Viktor. 🇺🇦 Слава Україні!
>
> --
> You received this message because you are subscribed to the Google Groups
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit https://groups.google.com/a/
> openssl.org/d/msgid/openssl-users/aYGjrdyC_2sZjREN%40chardros.imrryr.org.
>
--
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAEFUPH0h6EHK12aRTdc0_rb1ckXJvZLDANjM_d9vMzYDdyB2Fg%40mail.gmail.com.