WW Tools
All references

X.509 Extension and OID Reference

A certificate extension is an OID, a critical flag, and an opaque blob whose meaning depends entirely on that OID. Decoders print the names; this page is the lookup that tells you what each one does and whether you should care. The same OIDs drive the X.509 certificate decoder, so a value you see there has a row here.

Certificate extensions

OIDNameShort nameUsually criticalWhat it means
2.5.29.19Basic ConstraintsbasicConstraintsYesWhether this is a CA, and how many intermediates may sit below it (pathlen). CA:FALSE on a server certificate.
2.5.29.15Key UsagekeyUsageYesA bit field for what the key may do cryptographically. See the next table.
2.5.29.37Extended Key UsageextendedKeyUsageNoA list of OIDs for what the certificate is for: TLS server, TLS client, code signing, email.
2.5.29.17Subject Alternative NamesubjectAltNameNoThe hostnames, IPs, emails and URIs this certificate is valid for. The only place browsers look for a hostname.
2.5.29.18Issuer Alternative NameissuerAltNameNoAlternative names for the issuer. Rare in public PKI.
2.5.29.14Subject Key IdentifiersubjectKeyIdentifierNoA hash of this certificate's public key. Chain builders match it against a child's Authority Key Identifier.
2.5.29.35Authority Key IdentifierauthorityKeyIdentifierNoIdentifies the issuer's key, so a validator can pick the right parent when one CA has several keys.
2.5.29.31CRL Distribution PointscrlDistributionPointsNoWhere to fetch the revocation list. Fetching it is the client's job, not the certificate's.
1.3.6.1.5.5.7.1.1Authority Information AccessauthorityInfoAccessNoOCSP responder URL and a caIssuers URL for the issuing certificate. Browsers use caIssuers to paper over a missing intermediate; curl does not.
2.5.29.32Certificate PoliciescertificatePoliciesNoPolicy OIDs (DV, OV, EV) plus a CPS pointer to the CA's practice statement.
2.5.29.30Name ConstraintsnameConstraintsYesRestricts the names a CA below this one may issue for. The main tool for safely delegating a private CA.
2.5.29.36Policy ConstraintspolicyConstraintsYesForces explicit policy or forbids policy mapping further down the chain.
2.5.29.54Inhibit anyPolicyinhibitAnyPolicyYesStops the anyPolicy OID from satisfying policy checks below this certificate.
2.5.29.9Subject Directory AttributessubjectDirectoryAttributesNoExtra identifying attributes such as date of birth or place of birth. Used in national ID PKI, not TLS.
2.5.29.46Freshest CRLfreshestCRLNoWhere to fetch the delta CRL. Almost never populated in public PKI.
1.3.6.1.4.1.11129.2.4.2Signed Certificate Timestamp ListctPrecertSCTsNoCertificate Transparency proofs embedded by the CA. Chrome requires them for publicly trusted certificates.
1.3.6.1.5.5.7.1.24TLS Feature (OCSP must-staple)tlsFeatureNoCommits the server to stapling an OCSP response. Get it wrong and the site is unreachable, so it is rarely used.

A critical extension that a client does not recognize must cause it to reject the certificate, which is why the flag matters as much as the value.

Key Usage bits

BitNameWhat it permitsTypical on
0digitalSignatureSigning data, including TLS handshake signatures.TLS server and client certificates
1nonRepudiationSigning with a non-repudiation claim. Also called contentCommitment.Document and qualified signing certificates
2keyEnciphermentEncrypting a symmetric key with this public key.RSA TLS server certificates (not needed for ECDHE-only suites)
3dataEnciphermentEncrypting raw data directly with this key.Rare
4keyAgreementDeriving a shared secret, for example ECDH.Static EC key agreement certificates
5keyCertSignSigning other certificates. Requires CA:TRUE.Root and intermediate CAs
6cRLSignSigning a certificate revocation list.Root and intermediate CAs
7encipherOnlyWith keyAgreement, restricts the key to enciphering.Rare
8decipherOnlyWith keyAgreement, restricts the key to deciphering.Rare

RFC 5280 4.2.1.3 order, index 0 first. A decoder that prints names is reading these bit positions.

Extended Key Usage purposes

OIDNameWhat it is for
1.3.6.1.5.5.7.3.1serverAuthTLS server authentication. A server certificate without it is rejected when EKU is present.
1.3.6.1.5.5.7.3.2clientAuthTLS client authentication, which is what mTLS certificates carry.
1.3.6.1.5.5.7.3.3codeSigningSigning executables and packages.
1.3.6.1.5.5.7.3.4emailProtectionS/MIME signing and encryption.
1.3.6.1.5.5.7.3.8timeStampingSigning RFC 3161 timestamp tokens.
1.3.6.1.5.5.7.3.9OCSPSigningSigning OCSP responses on behalf of a CA.
2.5.29.37.0anyExtendedKeyUsageNo restriction. Treated by most validators as satisfying any purpose.
1.3.6.1.4.1.311.20.2.2msSmartCardLogonWindows smart card logon. Common in enterprise PKI.
1.3.6.1.4.1.311.10.3.4msEFSWindows Encrypting File System.
1.3.6.1.4.1.311.10.3.12msDocumentSigningMicrosoft Office document signing.
1.3.6.1.4.1.311.10.3.3msServerGatedCryptoLegacy Server Gated Crypto. Obsolete, still seen on old certificates.

DN attribute short names

ShortOIDName
CN2.5.4.3Common Name
O2.5.4.10Organization
OU2.5.4.11Organizational Unit
C2.5.4.6Country (two-letter code)
ST2.5.4.8State or Province
L2.5.4.7Locality
STREET2.5.4.9Street Address
postalCode2.5.4.17Postal Code
E1.2.840.113549.1.9.1Email Address
DC0.9.2342.19200300.100.1.25Domain Component
UID0.9.2342.19200300.100.1.1User ID
SERIALNUMBER2.5.4.5Serial Number (of the entity, not the certificate)
businessCategory2.5.4.15Business Category (EV)
jurisdictionC1.3.6.1.4.1.311.60.2.1.3Jurisdiction Country (EV)
jurisdictionST1.3.6.1.4.1.311.60.2.1.2Jurisdiction State or Province (EV)
jurisdictionL1.3.6.1.4.1.311.60.2.1.1Jurisdiction Locality (EV)

A distinguished name is printed as short names joined by commas, most general attribute first. An attribute with an OID outside this set prints as the dotted OID.

Frequently asked questions

Which extensions must a TLS server certificate have?

In practice: subjectAltName with every hostname it serves, basicConstraints with CA:FALSE, keyUsage with digitalSignature (plus keyEncipherment for RSA key exchange), and extendedKeyUsage containing serverAuth. Publicly trusted certificates also carry authorityKeyIdentifier, subjectKeyIdentifier, authorityInfoAccess and Certificate Transparency SCTs, all added by the CA. A certificate with no subjectAltName fails in every current browser regardless of what its Common Name says.

What does a critical extension mean?

Critical is a boolean on each extension. If a client does not recognize a critical extension, it must reject the certificate rather than ignore the extension. That is what makes nameConstraints useful: an old client that cannot enforce the constraint refuses the certificate instead of trusting it blindly. Marking something critical that clients do not understand is therefore a way to break your own certificate, which is why extensions like extendedKeyUsage are normally left non-critical.

Use the tool