Extended\Enhanced Key usage in Sub CA Certificates
i never add eku constraints in subordinate ca certificates reason.
i typically deploy application policies oid in eku extension ekus allowed.
the cases eku populated in ca certificates have seen are:
- root signing - customer has received subordinate ca certificate commercial provider. commercial provider limits eku through eku extension.
- cross certification. customer limits purposes partner's certificate trusted including eku oids in eku extension
hth,
brian
Windows Server > Security
Comments
Post a Comment