🗝️ Key Usage & Extended Key Usage Reference
What each X.509 Key Usage flag and Extended Key Usage (EKU) OID means, and where it's typically required.
Two extensions, two different jobs
The list above mixes entries from two X.509 extensions, and the type line tells you which is which. Key Usage (OID 2.5.29.15) is a bit string saying what the key may do at all: sign, encipher another key, agree a shared secret, sign certificates. Extended Key Usage (2.5.29.37) is a list of OIDs saying what the certificate is for: serving HTTPS, signing code, protecting mail. Both are normally marked critical, and software that sees a critical extension not covering the job in hand must refuse the certificate rather than shrug.
A public TLS server certificate carries digitalSignature in Key Usage and serverAuth in EKU. keyEncipherment only matters for the old RSA key-transport suites; TLS 1.3 removed them, so on a modern server it does nothing, and on an ECDSA key it is meaningless.
Setting them and reading them back
Extensions come from your openssl config section, not from the command line:
[ v3_req ]
keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth, clientAuth
subjectAltName = DNS:example.com
openssl x509 -in cert.pem -noout -ext keyUsage,extendedKeyUsage
Frequently asked questions
What key usage does a TLS server certificate need?
digitalSignature, plus the serverAuth EKU. Add keyEncipherment only if you still support TLS 1.2 clients negotiating RSA key exchange; with an ECDSA key, use digitalSignature alone.
What is OID 1.3.6.1.5.5.7.3.1?
serverAuth - TLS web server authentication. The whole family sits under the id-kp arc 1.3.6.1.5.5.7.3, so .2 is clientAuth, .3 code signing, .4 email protection, .8 timestamping and .9 OCSP signing.
Can I add an EKU to a certificate I have already been issued?
No. Extensions sit inside the signed portion, so changing one invalidates the CA's signature and every client rejects it. You have to request a reissue with the right profile.