Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sommer920471

#1
Hey all,

on OPNsense 26.7.2_2-amd64 my new ACME-issued certificate isn't assigned a "Purpose". Furthermore, when inspecting the response to the /api/trust/cert/search/ request, one can see, it's the only cert with an empty "cert_type" field (aka cert_type: ""). Also, when inspecting the "x509v3 Key Usage" field of the new certificate without a "Purpose", it only shows "Digital Signature", while my other certs, which have an assigned "Purpose", show "Key Encipherment" along "Digital Signature" in said field.
The only notable difference between this "Purpose"-less and my other ACME-issued certs is that this one was issued with Key type "Elliptic Curve secp384r1" instead of "RSA-4096".

Do you perhaps know the reason for this behavior?

Attached is a picture of the overview of some of my current certs to help you understand.

If you need any more information, please feel free to ask.

Best regards,
sommer920471