Certificate has no "Purpose" / "cert_type"

Started by sommer920471, August 19, 2026, 12:04:17 PM

Previous topic - Next topic
Hey all,

on OPNsense 26.7.2_2-amd64 my new ACME-issued certificate isn't assigned a "Purpose". Furthermore, when inspecting the response to the /api/trust/cert/search/ request, one can see, it's the only cert with an empty "cert_type" field (aka cert_type: ""). Also, when inspecting the "x509v3 Key Usage" field of the new certificate without a "Purpose", it only shows "Digital Signature", while my other certs, which have an assigned "Purpose", show "Key Encipherment" along "Digital Signature" in said field.
The only notable difference between this "Purpose"-less and my other ACME-issued certs is that this one was issued with Key type "Elliptic Curve secp384r1" instead of "RSA-4096".

Do you perhaps know the reason for this behavior?

Attached is a picture of the overview of some of my current certs to help you understand.

If you need any more information, please feel free to ask.

Best regards,
sommer920471

If I remember correctly, another member has already posted this issue, and it was gone after he rebooted OPNsense.

The cert was issued already in the previous version. Therefore, the machine already had a reboot.

Today at 11:04:44 AM #3 Last Edit: Today at 11:08:38 AM by Monviech (Cedrik)
If it's about ACME issued certificates, e.g. with the os-acme-client plugin, it's best if you open an issue here so the Maintainer of the plugin can see it.

Right now it's unclear if the ACME client persists these certificates wrong to the trust store, or the trust store fails to parse them correctly.

https://github.com/opnsense/plugins/issues

It could also be a core issue here:

https://github.com/opnsense/core/blob/f95e81516ee0e2fb184f06bb7f858d3dd45da9cc/src/opnsense/mvc/app/library/OPNsense/Trust/Store.php#L417-L440

If ECDSA only has a Digital Signature, "cert_type" could stay empty I assume.

Elliptic Curve secp384r1 makes the certificate use an ECDSA key.

extractPurpose() logic expects Digital Signature plus either Key Encipherment or Key Agreement, so the ECDSA cert probably through without a cert_type.

You can try an issue here: https://github.com/opnsense/core/issues
Hardware:
DEC740