Repository navigation
Ability to access certificate extensions through Crypto API X509Certificate class #48730
Description
Activity
- addedfeature requestIssues requesting new Node.js features.Issues requesting new Node.js features.
on Jul 10, 2023 Certificate extensions cal also allow access to CRL Distribution Points which are not in Authority Information Access field.
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on Jul 12, 2023 i created a pr hope it is a correct solution
I would be very happy if you have a comment
- changed the title
[-]Ability to access certificate extensions through `Cyrpto` API `x509` class[/-][+]Ability to access certificate extensions through `Crypto` API `X509Certificate` class[/+]on Jul 15, 2023 I am grateful @mertcanaltin is working on getting extensions into this API however it's concerning that the
.keyUsageproperty is actually hooked into the certificates "extended key usage" extension while there is also "key usage" extension. This caused some confusion for me that I'm sure many other people exploring this API will have.Reacted by Mert Can AltinThere has been no activity on this feature request for 5 months. To help maintain relevant open issues, please add the never-stale
Issues and PRs exempt from automated stale handling. label or close this issue if it should be closed. If not, the issue will be automatically closed 6 months after the last non-automated comment.
For more information on how the project manages feature requests, please consult the feature request management document.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Jun 9, 2024 github-actions commented
on Jul 10, 2024 on Jul 10, 2024 – with GitHub ActionsContributorMore actionsThere has been no activity on this feature request and it is being closed. If you feel closing this issue is not the right thing to do, please leave a comment.
For more information on how the project manages feature requests, please consult the feature request management document.
- removedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Aug 31, 2026 - addednever-staleIssues and PRs exempt from automated stale handling.Issues and PRs exempt from automated stale handling.
on Sep 23, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsIn Progress
What is the problem this feature will solve?
Key usages (not extend) are completely different and can only be accessed through certificate extension under OID 2.5.29.15 which contains value in a bit array format.
Key usage can have for definition: Digital signature, Non-repudiation, Key encipherment, Data encipherment, Key agreement, Certificate signing, CRL signing, Encipher only, Decipher only.
As of now Crypto API only provides access to Extended Key usage under the
x509.keyUsagebut does not provide access to the Key Usage through the certificate Extensions part.What is the feature you are proposing to solve the problem?
Having a method the class
x509that can allow to have access to the Extension part of a certificate through a safe structure.What alternatives have you considered?
Using 3rd party libraries like PKIjs or Forge, but I would like a native feature instead.