Removing "Smallstep CA Provisioner ID" X509 Extension from Certificate #1465
Replies: 2 comments 1 reply
-
Hey @frank-park, currently we don't support disabling the extension from being added. We rely on the value of the extension when a certificate is renewed via the We have an open issue tracking this functionality: #620. You can give it a thumbs-up and/or add your use case to it for more context. What's the reason you would like the extension to not exist in the issued certificate? We're not marking it critical, so a compliant system should ignore the unknown extension. Of course in practice this may not be the case 😅 |
Beta Was this translation helpful? Give feedback.
-
Just mentioning here that there are a couple of PR addressing this discussion. Once merged, you will be able to disable the smallstep extensions per provisioner or globally. |
Beta Was this translation helpful? Give feedback.
-
Is there any way to remove the "Smallstep CA Provisioner ID" extension (1.3.6.1.4.1.37476.9000.64.1) from the certificates being created by step-ca?
Beta Was this translation helpful? Give feedback.
All reactions