Re: openssl x509 certificate question
SIMON BABY <[email protected]> Tue, 3 Feb 2026 08:25:37 -0800
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CAEFUPH0XY+k5qgQ=+w5Hgd+guUF3jaafTB7Azx8O-BCi-0T1Tw@mail.gmail.com> |
Thank you Viktor On Tuesday, February 3, 2026, Viktor Dukhovni <[email protected]> wrote: > On Tue, Feb 03, 2026 at 03:04:20AM -0800, SIMON BABY wrote: > > > Thank you for the clarification . Yes I was asking about the case where > all > > the extensions are empty in root CA and intermediate CA as well. > > > > So in your example what happen if the below fields are also empty ? > > > > X509v3 extensions: > > X509v3 Basic Constraints: critical > > CA:TRUE, pathlen:0 > > X509v3 Key Usage: critical > > Certificate Sign, CRL Sign > > X509v3 Subject Key Identifier: > > 5A:8C:87:49:BF:97:DC:64:30:53: > 2B:49:F1:0D:57:45:70:FF:EA:92 > > X509v3 Authority Key Identifier: > > D9:D8:10:05:D5:E2:82:20:98:79: > 8A:57:B6:76:5D:43:0D:54:86:AE > > > > Do we have any RFC saying about the mandatory and optional extensions in > > CA’s and user certs ? > > That's an interesting theoretical question, but I am curious why you > feel it is important to pursue this line of inquiry. There is little > reason to not simply include these common CA extensions in your CA > certificates. > > You can read RFC5280, but odn't confuse many of its interoperability > "recommendations" with absolute requirements, there is no IETF police, > and not all implementations do or should enforce every requirement > ("recommendation") in that RFC. And yet, it is a good idea to conform > whenever possible. > > FWIW, OpenSSL allows some or all of these extensions to be missing, but > there's no reason to push your luck, other implementations may be less > tolerant. > > -- > Viktor. 🇺🇦 Слава Україні! > > -- > You received this message because you are subscribed to the Google Groups > "openssl-users" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org > To view this discussion visit https://groups.google.com/a/ > openssl.org/d/msgid/openssl-users/aYH-thr8JOTNamra%40chardros.imrryr.org. > -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAEFUPH0XY%2Bk5qgQ%3D%2Bw5Hgd%2BguUF3jaafTB7Azx8O-BCi-0T1Tw%40mail.gmail.com.