Re: openssl x509 certificate question

Viktor Dukhovni <[email protected]> Wed, 4 Feb 2026 00:57:10 +1100
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On Tue, Feb 03, 2026 at 03:04:20AM -0800, SIMON BABY wrote:

> Thank you for the clarification . Yes I was asking about the case where all
> the extensions are empty in root CA and intermediate CA as well.
> 
> So in your example what happen if the below fields are also empty ?
> 
>      X509v3 extensions:
>                 X509v3 Basic Constraints: critical
>                     CA:TRUE, pathlen:0
>                 X509v3 Key Usage: critical
>                     Certificate Sign, CRL Sign
>                 X509v3 Subject Key Identifier:
>                     5A:8C:87:49:BF:97:DC:64:30:53:2B:49:F1:0D:57:45:70:FF:EA:92
>                 X509v3 Authority Key Identifier:
>                     D9:D8:10:05:D5:E2:82:20:98:79:8A:57:B6:76:5D:43:0D:54:86:AE
> 
> Do we have any RFC saying  about the mandatory and optional extensions in
> CA’s and user certs ?

That's an interesting theoretical question, but I am curious why you
feel it is important to pursue this line of inquiry.  There is little
reason to not simply include these common CA extensions in your CA
certificates.

You can read RFC5280, but odn't confuse many of its interoperability
"recommendations" with absolute requirements, there is no IETF police,
and not all implementations do or should enforce every requirement
("recommendation") in that RFC.  And yet, it is a good idea to conform
whenever possible.

FWIW, OpenSSL allows some or all of these extensions to be missing, but
there's no reason to push your luck, other implementations may be less
tolerant.

-- 
    Viktor.  🇺🇦 Слава Україні!

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aYH-thr8JOTNamra%40chardros.imrryr.org.