Skip to content

Ability to access certificate extensions through Crypto API X509Certificate class #48730

Description

@jeffsec-aws

What is the problem this feature will solve?

Key usages (not extend) are completely different and can only be accessed through certificate extension under OID 2.5.29.15 which contains value in a bit array format.

Key usage can have for definition: Digital signature, Non-repudiation, Key encipherment, Data encipherment, Key agreement, Certificate signing, CRL signing, Encipher only, Decipher only.

As of now Crypto API only provides access to Extended Key usage under the x509.keyUsage but does not provide access to the Key Usage through the certificate Extensions part.

What is the feature you are proposing to solve the problem?

Having a method the class x509 that can allow to have access to the Extension part of a certificate through a safe structure.

What alternatives have you considered?

Using 3rd party libraries like PKIjs or Forge, but I would like a native feature instead.

Activity

  1. jeffsec-aws commented on Jul 10, 2023

    @jeffsec-aws
    Author

    Certificate extensions cal also allow access to CRL Distribution Points which are not in Authority Information Access field.

  2. added
    cryptoIssues and PRs related to the crypto subsystem.
    on Jul 12, 2023
  3. mertcanaltin commented on Jul 15, 2023

    @mertcanaltin
    Member

    i created a pr hope it is a correct solution

    I would be very happy if you have a comment

    #48780

    @jeffsec-aws

  4. changed the title [-]Ability to access certificate extensions through `Cyrpto` API `x509` class[/-] [+]Ability to access certificate extensions through `Crypto` API `X509Certificate` class[/+] on Jul 15, 2023
  5. brianorwhatever commented on Dec 11, 2023

    @brianorwhatever

    I am grateful @mertcanaltin is working on getting extensions into this API however it's concerning that the .keyUsage property is actually hooked into the certificates "extended key usage" extension while there is also "key usage" extension. This caused some confusion for me that I'm sure many other people exploring this API will have.

  6. github-actions commented on Jun 9, 2024

    @github-actions
    Contributor

    There has been no activity on this feature request for 5 months. To help maintain relevant open issues, please add the never-stale Issues and PRs exempt from automated stale handling. label or close this issue if it should be closed. If not, the issue will be automatically closed 6 months after the last non-automated comment.
    For more information on how the project manages feature requests, please consult the feature request management document.

  7. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 9, 2024
  8. github-actions commented on Jul 10, 2024

    @github-actions
    Contributor

    There has been no activity on this feature request and it is being closed. If you feel closing this issue is not the right thing to do, please leave a comment.

    For more information on how the project manages feature requests, please consult the feature request management document.

  9. reopened this on Aug 31, 2026
  10. removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Aug 31, 2026
  11. moved this from Awaiting Triage to In Progress in Node.js feature requestson Aug 31, 2026
  12. added
    never-staleIssues and PRs exempt from automated stale handling.
    on Sep 23, 2026
  13. self-assigned this
    on Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cryptoIssues and PRs related to the crypto subsystem.feature requestIssues requesting new Node.js features.never-staleIssues and PRs exempt from automated stale handling.

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions