Extended Key Usage
There can be one or more such key purposes defined. This extension is usually defined by the end entity systems in their certificates to support their security design constraints. When EKU is present in a certificate, it implies that the public key can be used in addition to or in place of the basic purposes listed in the key usage extension. The EKU extension is always tagged as critical.
The feature enables PKI clients like TLS or IKE to include EKU extension in their certificates and also process received EKU enabled certificates from peer and take action (accept or reject a connection). The EKU extension has key purposes as follows:
- Server authentication (OID 1.3.6.1.5.5.7.3.1)
- Client Authentication (OID 1.3.6.1.5.5.7.3.2)
- anyExtendedKeyUsage (OID 2.5.29.37.0)
Every fields are uniquely identified by an OID.
System in FIPS Mode
Upon receiving a peer certificate:
- For an IKE client, if peer certificate contains an EKU without "anyExtendedKeyUsage" set, the certificate is rejected. If the peer certificate does not contain the EKU extension, the certificate is accepted.
- For a TLS client, if peer certificate does not have an EKU extension, or contains an EKU without server authentication set, the certificate is rejected.
System in Non-FIPS Mode
Upon receiving a peer certificate:
- For an IKE client, if peer certificate contains an EKU without "anyExtendedKeyUsage" set, the certificate is rejected. If the peer certificate does not contain the EKU extension, the certificate is accepted.
- For a TLS client, if peer certificate does not have an EKU extension, the certificate is accepted. If the EKU extension is available without server authentication set, the certificate is rejected.
Configuration
The EKU extension is not enabled by default in the certificate. The PKI client (like
IKE/TLS) has to provision it explicitly using the
extended-key-usage command.
device(config)#pki trustpoint <trust-point name> device(config-pki-trustpoint-trust1)#extended-key-usage ? client-auth Enable client authentication. server-auth Enable server authentication. any Enable any extended key
The NO form of this command disables the EKU extension.