Re: [OpenXPKI-users] Extensions: key usage: how to have only "key usage" asked by the CSR

2021-12-01 Thread Martin Bartosch via OpenXPKI-users
Hi, > I'm guessing this has been already asked, I searched the archives to no avail. No, as far as I am concerned I have never seen this requirement before. > I generate my CSR with key usage information “DigitalSignature” and “Key > encipherment” (using OpenSSL API). > But when I get my enroll

[OpenXPKI-users] Extensions: key usage: how to have only "key usage" asked by the CSR

2021-12-01 Thread Eddy BODIN via OpenXPKI-users
Hi, I'm guessing this has been already asked, I searched the archives to no avail. I generate my CSR with key usage information "DigitalSignature" and "Key encipherment" (using OpenSSL API). But when I get my enrolled certificate I have a new key usage "key agreement". I saw is configurable in tls