Entrust PKI as a Service

issuing

Entrust provides the basic-ca-subord profiles for certificate issuing authorities.


⚠ This profile is not exposed nor configurable.


Certificate fields

The basic-ca-subord profile set the following certificate fields.

Field basic-ca-subord
Issuer Customer’s online root or issuing CA
Subject No constraint
Validity period Less than or equal to 10 years

Certificate critical extensions

The basic-ca-subord profile set the following certificate critical extensions.

Extension Value
Basic Constraints cA=True, pathLenConstraint=0
Extended Key Usage Never present
Key Usage digitalSignature, keyCertSign, cRLSign

Certificate non-critical extensions

The basic-ca-subord profile set the following non-critical certificate extensions.

Extension Value
AIA Supplied when the customer enables OCSP on CA creation
Authority Key Identifier Matches the subjectKeyIdentifier of the signing certificate
CRL Distribution Points Always present
OCSP Never present
Subject Key Identifier «The leftmost 160-bits of the SHA-256 hash of the value of the BIT STRING subjectPublicKey» as described in RFC 7093 section 2