Re: openssl x509 certificate question

SIMON BABY <[email protected]> Tue, 3 Feb 2026 08:25:37 -0800
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <CAEFUPH0XY+k5qgQ=+w5Hgd+guUF3jaafTB7Azx8O-BCi-0T1Tw@mail.gmail.com>
Thank you Viktor

On Tuesday, February 3, 2026, Viktor Dukhovni <[email protected]>
wrote:

> On Tue, Feb 03, 2026 at 03:04:20AM -0800, SIMON BABY wrote:
>
> > Thank you for the clarification . Yes I was asking about the case where
> all
> > the extensions are empty in root CA and intermediate CA as well.
> >
> > So in your example what happen if the below fields are also empty ?
> >
> >      X509v3 extensions:
> >                 X509v3 Basic Constraints: critical
> >                     CA:TRUE, pathlen:0
> >                 X509v3 Key Usage: critical
> >                     Certificate Sign, CRL Sign
> >                 X509v3 Subject Key Identifier:
> >                     5A:8C:87:49:BF:97:DC:64:30:53:
> 2B:49:F1:0D:57:45:70:FF:EA:92
> >                 X509v3 Authority Key Identifier:
> >                     D9:D8:10:05:D5:E2:82:20:98:79:
> 8A:57:B6:76:5D:43:0D:54:86:AE
> >
> > Do we have any RFC saying  about the mandatory and optional extensions in
> > CA’s and user certs ?
>
> That's an interesting theoretical question, but I am curious why you
> feel it is important to pursue this line of inquiry.  There is little
> reason to not simply include these common CA extensions in your CA
> certificates.
>
> You can read RFC5280, but odn't confuse many of its interoperability
> "recommendations" with absolute requirements, there is no IETF police,
> and not all implementations do or should enforce every requirement
> ("recommendation") in that RFC.  And yet, it is a good idea to conform
> whenever possible.
>
> FWIW, OpenSSL allows some or all of these extensions to be missing, but
> there's no reason to push your luck, other implementations may be less
> tolerant.
>
> --
>     Viktor.  🇺🇦 Слава Україні!
>
> --
> You received this message because you are subscribed to the Google Groups
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit https://groups.google.com/a/
> openssl.org/d/msgid/openssl-users/aYH-thr8JOTNamra%40chardros.imrryr.org.
>

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAEFUPH0XY%2Bk5qgQ%3D%2Bw5Hgd%2BguUF3jaafTB7Azx8O-BCi-0T1Tw%40mail.gmail.com.