X.509 Extension and OID Reference
A certificate extension is an OID, a critical flag, and an opaque blob whose meaning depends entirely on that OID. Decoders print the names; this page is the lookup that tells you what each one does and whether you should care. The same OIDs drive the X.509 certificate decoder, so a value you see there has a row here.
Certificate extensions
| OID | Name | Short name | Usually critical | What it means |
|---|---|---|---|---|
| 2.5.29.19 | Basic Constraints | basicConstraints | Yes | Whether this is a CA, and how many intermediates may sit below it (pathlen). CA:FALSE on a server certificate. |
| 2.5.29.15 | Key Usage | keyUsage | Yes | A bit field for what the key may do cryptographically. See the next table. |
| 2.5.29.37 | Extended Key Usage | extendedKeyUsage | No | A list of OIDs for what the certificate is for: TLS server, TLS client, code signing, email. |
| 2.5.29.17 | Subject Alternative Name | subjectAltName | No | The hostnames, IPs, emails and URIs this certificate is valid for. The only place browsers look for a hostname. |
| 2.5.29.18 | Issuer Alternative Name | issuerAltName | No | Alternative names for the issuer. Rare in public PKI. |
| 2.5.29.14 | Subject Key Identifier | subjectKeyIdentifier | No | A hash of this certificate's public key. Chain builders match it against a child's Authority Key Identifier. |
| 2.5.29.35 | Authority Key Identifier | authorityKeyIdentifier | No | Identifies the issuer's key, so a validator can pick the right parent when one CA has several keys. |
| 2.5.29.31 | CRL Distribution Points | crlDistributionPoints | No | Where to fetch the revocation list. Fetching it is the client's job, not the certificate's. |
| 1.3.6.1.5.5.7.1.1 | Authority Information Access | authorityInfoAccess | No | OCSP responder URL and a caIssuers URL for the issuing certificate. Browsers use caIssuers to paper over a missing intermediate; curl does not. |
| 2.5.29.32 | Certificate Policies | certificatePolicies | No | Policy OIDs (DV, OV, EV) plus a CPS pointer to the CA's practice statement. |
| 2.5.29.30 | Name Constraints | nameConstraints | Yes | Restricts the names a CA below this one may issue for. The main tool for safely delegating a private CA. |
| 2.5.29.36 | Policy Constraints | policyConstraints | Yes | Forces explicit policy or forbids policy mapping further down the chain. |
| 2.5.29.54 | Inhibit anyPolicy | inhibitAnyPolicy | Yes | Stops the anyPolicy OID from satisfying policy checks below this certificate. |
| 2.5.29.9 | Subject Directory Attributes | subjectDirectoryAttributes | No | Extra identifying attributes such as date of birth or place of birth. Used in national ID PKI, not TLS. |
| 2.5.29.46 | Freshest CRL | freshestCRL | No | Where to fetch the delta CRL. Almost never populated in public PKI. |
| 1.3.6.1.4.1.11129.2.4.2 | Signed Certificate Timestamp List | ctPrecertSCTs | No | Certificate Transparency proofs embedded by the CA. Chrome requires them for publicly trusted certificates. |
| 1.3.6.1.5.5.7.1.24 | TLS Feature (OCSP must-staple) | tlsFeature | No | Commits the server to stapling an OCSP response. Get it wrong and the site is unreachable, so it is rarely used. |
A critical extension that a client does not recognize must cause it to reject the certificate, which is why the flag matters as much as the value.
Key Usage bits
| Bit | Name | What it permits | Typical on |
|---|---|---|---|
| 0 | digitalSignature | Signing data, including TLS handshake signatures. | TLS server and client certificates |
| 1 | nonRepudiation | Signing with a non-repudiation claim. Also called contentCommitment. | Document and qualified signing certificates |
| 2 | keyEncipherment | Encrypting a symmetric key with this public key. | RSA TLS server certificates (not needed for ECDHE-only suites) |
| 3 | dataEncipherment | Encrypting raw data directly with this key. | Rare |
| 4 | keyAgreement | Deriving a shared secret, for example ECDH. | Static EC key agreement certificates |
| 5 | keyCertSign | Signing other certificates. Requires CA:TRUE. | Root and intermediate CAs |
| 6 | cRLSign | Signing a certificate revocation list. | Root and intermediate CAs |
| 7 | encipherOnly | With keyAgreement, restricts the key to enciphering. | Rare |
| 8 | decipherOnly | With keyAgreement, restricts the key to deciphering. | Rare |
RFC 5280 4.2.1.3 order, index 0 first. A decoder that prints names is reading these bit positions.
Extended Key Usage purposes
| OID | Name | What it is for |
|---|---|---|
| 1.3.6.1.5.5.7.3.1 | serverAuth | TLS server authentication. A server certificate without it is rejected when EKU is present. |
| 1.3.6.1.5.5.7.3.2 | clientAuth | TLS client authentication, which is what mTLS certificates carry. |
| 1.3.6.1.5.5.7.3.3 | codeSigning | Signing executables and packages. |
| 1.3.6.1.5.5.7.3.4 | emailProtection | S/MIME signing and encryption. |
| 1.3.6.1.5.5.7.3.8 | timeStamping | Signing RFC 3161 timestamp tokens. |
| 1.3.6.1.5.5.7.3.9 | OCSPSigning | Signing OCSP responses on behalf of a CA. |
| 2.5.29.37.0 | anyExtendedKeyUsage | No restriction. Treated by most validators as satisfying any purpose. |
| 1.3.6.1.4.1.311.20.2.2 | msSmartCardLogon | Windows smart card logon. Common in enterprise PKI. |
| 1.3.6.1.4.1.311.10.3.4 | msEFS | Windows Encrypting File System. |
| 1.3.6.1.4.1.311.10.3.12 | msDocumentSigning | Microsoft Office document signing. |
| 1.3.6.1.4.1.311.10.3.3 | msServerGatedCrypto | Legacy Server Gated Crypto. Obsolete, still seen on old certificates. |
DN attribute short names
| Short | OID | Name |
|---|---|---|
| CN | 2.5.4.3 | Common Name |
| O | 2.5.4.10 | Organization |
| OU | 2.5.4.11 | Organizational Unit |
| C | 2.5.4.6 | Country (two-letter code) |
| ST | 2.5.4.8 | State or Province |
| L | 2.5.4.7 | Locality |
| STREET | 2.5.4.9 | Street Address |
| postalCode | 2.5.4.17 | Postal Code |
| E | 1.2.840.113549.1.9.1 | Email Address |
| DC | 0.9.2342.19200300.100.1.25 | Domain Component |
| UID | 0.9.2342.19200300.100.1.1 | User ID |
| SERIALNUMBER | 2.5.4.5 | Serial Number (of the entity, not the certificate) |
| businessCategory | 2.5.4.15 | Business Category (EV) |
| jurisdictionC | 1.3.6.1.4.1.311.60.2.1.3 | Jurisdiction Country (EV) |
| jurisdictionST | 1.3.6.1.4.1.311.60.2.1.2 | Jurisdiction State or Province (EV) |
| jurisdictionL | 1.3.6.1.4.1.311.60.2.1.1 | Jurisdiction Locality (EV) |
A distinguished name is printed as short names joined by commas, most general attribute first. An attribute with an OID outside this set prints as the dotted OID.
Frequently asked questions
Which extensions must a TLS server certificate have?
In practice: subjectAltName with every hostname it serves, basicConstraints with CA:FALSE, keyUsage with digitalSignature (plus keyEncipherment for RSA key exchange), and extendedKeyUsage containing serverAuth. Publicly trusted certificates also carry authorityKeyIdentifier, subjectKeyIdentifier, authorityInfoAccess and Certificate Transparency SCTs, all added by the CA. A certificate with no subjectAltName fails in every current browser regardless of what its Common Name says.
What does a critical extension mean?
Critical is a boolean on each extension. If a client does not recognize a critical extension, it must reject the certificate rather than ignore the extension. That is what makes nameConstraints useful: an old client that cannot enforce the constraint refuses the certificate instead of trusting it blindly. Marking something critical that clients do not understand is therefore a way to break your own certificate, which is why extensions like extendedKeyUsage are normally left non-critical.