webui.crypto.csr_profiles ========================= Return predefined CSR profiles for common certificate roles. There is a profile for each combination of role (a TLS server certificate, or a TLS client certificate used when TrueNAS authenticates itself to a remote service) and key type (RSA or EC). Each one provides recommended defaults for the key parameters, the digest algorithm, and the X.509 extensions (basic constraints, key usage, extended key usage). The profiles are advisory: they are intended to prefill the CSR form and are not applied by :doc:`certificate.create `, which must be passed these values explicitly. .. raw:: html
Type: object

Type: array
No Additional Items

CSRProfilesModel

Type: object
Default:
{ "TLS Server (e.g. Web UI, FTPS, Apps) - RSA": { "cert_extensions": { "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true, "key_encipherment": true } }, "digest_algorithm": "SHA256", "key_length": 2048, "key_type": "RSA" }, "TLS Server (e.g. Web UI, FTPS, Apps) - EC": { "cert_extensions": { "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }, "digest_algorithm": "SHA256", "ec_curve": "SECP384R1", "key_type": "EC" }, "TLS Client (e.g. Syslog, LDAP, KMIP) - RSA": { "cert_extensions": { "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }, "digest_algorithm": "SHA256", "key_length": 2048, "key_type": "RSA" }, "TLS Client (e.g. Syslog, LDAP, KMIP) - EC": { "cert_extensions": { "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }, "digest_algorithm": "SHA256", "ec_curve": "SECP384R1", "key_type": "EC" } }

Predefined certificate profiles for common use cases.

No Additional Properties

TLSServerRSAProfile

Type: object

RSA certificate for services where TrueNAS accepts incoming TLS connections, such as the web UI, FTPS, and apps. Requests TLS Web Server Authentication only, which every public and ACME CA accepts.

No Additional Properties

ServerRSACSRExtensionsModel

Type: object
Default:
{ "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true, "key_encipherment": true } }

Certificate extensions configuration for RSA certificates.

No Additional Properties

BasicConstraintsModel

Type: object
Default:
{ "enabled": true, "ca": false, "extension_critical": true }

Basic constraints extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the basic constraints extension is enabled.

Ca

Type: boolean Default: false

Whether this certificate can act as a certificate authority.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

ServerAuthExtendedKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }

Extended key usage extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the extended key usage extension is enabled.

Extension Critical

Type: boolean Default: false

Whether this extension is marked as critical.

Usages

Type: array of string

Array of extended key usage purposes for the certificate.

No Additional Items
Each item of this array must be:
Type: string

ServerRSAKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": true, "digital_signature": true, "key_encipherment": true }

Key usage extension configuration for RSA certificates.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the key usage extension is enabled.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

Digital Signature

Type: boolean Default: true

Whether the key can be used for digital signatures.

Key Encipherment

Type: boolean Default: true

Whether the key can be used for key encipherment.

Key Length

Type: integer Default: 2048

RSA key length in bits.

Key Type

Type: string Default: "RSA"

Type of cryptographic key (RSA).

Digest Algorithm

Type: string Default: "SHA256"

Hash algorithm for certificate signing.

TLSServerECProfile

Type: object

Elliptic curve certificate for services where TrueNAS accepts incoming TLS connections, such as the web UI, FTPS, and apps. Requests TLS Web Server Authentication only, which every public and ACME CA accepts.

No Additional Properties

ServerECCSRExtensionsModel

Type: object
Default:
{ "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }

Certificate extensions configuration for EC certificates.

No Additional Properties

BasicConstraintsModel

Type: object
Default:
{ "enabled": true, "ca": false, "extension_critical": true }

Basic constraints extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the basic constraints extension is enabled.

Ca

Type: boolean Default: false

Whether this certificate can act as a certificate authority.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

ServerAuthExtendedKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": false, "usages": [ "SERVER_AUTH" ] }

Extended key usage extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the extended key usage extension is enabled.

Extension Critical

Type: boolean Default: false

Whether this extension is marked as critical.

Usages

Type: array of string

Array of extended key usage purposes for the certificate.

No Additional Items
Each item of this array must be:
Type: string

SigningKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": true, "digital_signature": true }

Key usage extension configuration for EC certificates.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the key usage extension is enabled.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

Digital Signature

Type: boolean Default: true

Whether the key can be used for digital signatures.

Ec Curve

Type: string Default: "SECP384R1"

Elliptic curve to use for key generation.

Key Type

Type: string Default: "EC"

Type of cryptographic key (EC).

Digest Algorithm

Type: string Default: "SHA256"

Hash algorithm for certificate signing.

TLSClientRSAProfile

Type: object

RSA certificate for services where TrueNAS connects out and must authenticate itself, such as remote syslog over TLS, LDAP mutual TLS, and KMIP. Requests TLS Web Client Authentication and is intended for a private CA.

No Additional Properties

ClientCSRExtensionsModel

Type: object
Default:
{ "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }

Certificate extensions configuration for RSA certificates.

No Additional Properties

BasicConstraintsModel

Type: object
Default:
{ "enabled": true, "ca": false, "extension_critical": true }

Basic constraints extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the basic constraints extension is enabled.

Ca

Type: boolean Default: false

Whether this certificate can act as a certificate authority.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

ClientAuthExtendedKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }

Extended key usage extension configuration.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the extended key usage extension is enabled.

Extension Critical

Type: boolean Default: false

Whether this extension is marked as critical.

Usages

Type: array of string

Array of extended key usage purposes for the certificate.

No Additional Items
Each item of this array must be:
Type: string

SigningKeyUsageModel

Type: object
Default:
{ "enabled": true, "extension_critical": true, "digital_signature": true }

Key usage extension configuration for client certificates.

No Additional Properties

Enabled

Type: boolean Default: true

Whether the key usage extension is enabled.

Extension Critical

Type: boolean Default: true

Whether this extension is marked as critical.

Digital Signature

Type: boolean Default: true

Whether the key can be used for digital signatures.

Key Length

Type: integer Default: 2048

RSA key length in bits.

Key Type

Type: string Default: "RSA"

Type of cryptographic key (RSA).

Digest Algorithm

Type: string Default: "SHA256"

Hash algorithm for certificate signing.

TLSClientECProfile

Type: object

Elliptic curve certificate for services where TrueNAS connects out and must authenticate itself, such as remote syslog over TLS, LDAP mutual TLS, and KMIP. Requests TLS Web Client Authentication and is intended for a private CA.

No Additional Properties

ClientCSRExtensionsModel

Type: object
Default:
{ "BasicConstraints": { "ca": false, "enabled": true, "extension_critical": true }, "ExtendedKeyUsage": { "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }, "KeyUsage": { "digital_signature": true, "enabled": true, "extension_critical": true } }

Certificate extensions configuration for EC certificates.

No Additional Properties

Type: object
Default:
{ "enabled": true, "ca": false, "extension_critical": true }

Basic constraints extension configuration.

Type: object
Default:
{ "enabled": true, "extension_critical": false, "usages": [ "CLIENT_AUTH" ] }

Extended key usage extension configuration.

Type: object
Default:
{ "enabled": true, "extension_critical": true, "digital_signature": true }

Key usage extension configuration for client certificates.

Ec Curve

Type: string Default: "SECP384R1"

Elliptic curve to use for key generation.

Key Type

Type: string Default: "EC"

Type of cryptographic key (EC).

Digest Algorithm

Type: string Default: "SHA256"

Hash algorithm for certificate signing.



*Required roles:* CERTIFICATE_READ