webui.crypto.csr_profiles¶
Return predefined CSR profiles for common certificate roles.
There is a profile for each combination of role (a TLS server certificate, or a TLS client certificate used when TrueNAS authenticates itself to a remote service) and key type (RSA or EC). Each one provides recommended defaults for the key parameters, the digest algorithm, and the X.509 extensions (basic constraints, key usage, extended key usage).
The profiles are advisory: they are intended to prefill the CSR form and are not applied by certificate.create, which must be passed these values explicitly.
No Additional Items
CSRProfilesModel
Type: objectPredefined certificate profiles for common use cases.
No Additional PropertiesTLSServerRSAProfile
Type: objectRSA certificate for services where TrueNAS accepts incoming TLS connections, such as the web UI, FTPS, and apps. Requests TLS Web Server Authentication only, which every public and ACME CA accepts.
No Additional PropertiesServerRSACSRExtensionsModel
Type: objectCertificate extensions configuration for RSA certificates.
No Additional PropertiesBasicConstraintsModel
Type: objectBasic constraints extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the basic constraints extension is enabled.
Ca
Type: boolean Default: falseWhether this certificate can act as a certificate authority.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
ServerAuthExtendedKeyUsageModel
Type: objectExtended key usage extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the extended key usage extension is enabled.
Extension Critical
Type: boolean Default: falseWhether this extension is marked as critical.
Usages
Type: array of stringArray of extended key usage purposes for the certificate.
No Additional ItemsEach item of this array must be:
ServerRSAKeyUsageModel
Type: objectKey usage extension configuration for RSA certificates.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the key usage extension is enabled.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
Digital Signature
Type: boolean Default: trueWhether the key can be used for digital signatures.
Key Encipherment
Type: boolean Default: trueWhether the key can be used for key encipherment.
Key Length
Type: integer Default: 2048RSA key length in bits.
Key Type
Type: string Default: "RSA"Type of cryptographic key (RSA).
Digest Algorithm
Type: string Default: "SHA256"Hash algorithm for certificate signing.
TLSServerECProfile
Type: objectElliptic curve certificate for services where TrueNAS accepts incoming TLS connections, such as the web UI, FTPS, and apps. Requests TLS Web Server Authentication only, which every public and ACME CA accepts.
No Additional PropertiesServerECCSRExtensionsModel
Type: objectCertificate extensions configuration for EC certificates.
No Additional PropertiesBasicConstraintsModel
Type: objectBasic constraints extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the basic constraints extension is enabled.
Ca
Type: boolean Default: falseWhether this certificate can act as a certificate authority.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
ServerAuthExtendedKeyUsageModel
Type: objectExtended key usage extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the extended key usage extension is enabled.
Extension Critical
Type: boolean Default: falseWhether this extension is marked as critical.
Usages
Type: array of stringArray of extended key usage purposes for the certificate.
No Additional ItemsEach item of this array must be:
SigningKeyUsageModel
Type: objectKey usage extension configuration for EC certificates.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the key usage extension is enabled.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
Digital Signature
Type: boolean Default: trueWhether the key can be used for digital signatures.
Ec Curve
Type: string Default: "SECP384R1"Elliptic curve to use for key generation.
Key Type
Type: string Default: "EC"Type of cryptographic key (EC).
Digest Algorithm
Type: string Default: "SHA256"Hash algorithm for certificate signing.
TLSClientRSAProfile
Type: objectRSA certificate for services where TrueNAS connects out and must authenticate itself, such as remote syslog over TLS, LDAP mutual TLS, and KMIP. Requests TLS Web Client Authentication and is intended for a private CA.
No Additional PropertiesClientCSRExtensionsModel
Type: objectCertificate extensions configuration for RSA certificates.
No Additional PropertiesBasicConstraintsModel
Type: objectBasic constraints extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the basic constraints extension is enabled.
Ca
Type: boolean Default: falseWhether this certificate can act as a certificate authority.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
ClientAuthExtendedKeyUsageModel
Type: objectExtended key usage extension configuration.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the extended key usage extension is enabled.
Extension Critical
Type: boolean Default: falseWhether this extension is marked as critical.
Usages
Type: array of stringArray of extended key usage purposes for the certificate.
No Additional ItemsEach item of this array must be:
SigningKeyUsageModel
Type: objectKey usage extension configuration for client certificates.
No Additional PropertiesEnabled
Type: boolean Default: trueWhether the key usage extension is enabled.
Extension Critical
Type: boolean Default: trueWhether this extension is marked as critical.
Digital Signature
Type: boolean Default: trueWhether the key can be used for digital signatures.
Key Length
Type: integer Default: 2048RSA key length in bits.
Key Type
Type: string Default: "RSA"Type of cryptographic key (RSA).
Digest Algorithm
Type: string Default: "SHA256"Hash algorithm for certificate signing.
TLSClientECProfile
Type: objectElliptic curve certificate for services where TrueNAS connects out and must authenticate itself, such as remote syslog over TLS, LDAP mutual TLS, and KMIP. Requests TLS Web Client Authentication and is intended for a private CA.
No Additional PropertiesClientCSRExtensionsModel
Type: objectCertificate extensions configuration for EC certificates.
No Additional PropertiesBasic constraints extension configuration.
Extended key usage extension configuration.
Key usage extension configuration for client certificates.
Ec Curve
Type: string Default: "SECP384R1"Elliptic curve to use for key generation.
Key Type
Type: string Default: "EC"Type of cryptographic key (EC).
Digest Algorithm
Type: string Default: "SHA256"Hash algorithm for certificate signing.
Required roles: CERTIFICATE_READ