<div dir="ltr"><div>Hi.</div><div><br></div>A service with which we integrate recently refused to trust a new IDP certificate (they require a custom 2-year cert..) because it contained a "Basic Constraints" CA:TRUE in the extensions section; in particular it had the "critical" switch turned on, which is probably what triggered the rejection.  The cert we previously gave them had CA:TRUE but did <b>not</b> have "critical" set.<br><br>X509v3 Basic Constraints: critical<br>       CA:TRUE<br><br>This was my first knowledge of this extension.  I've since learned that the defaults of these settings can vary depending on your OpenSSL version -- which is probably how I stumbled into this.  The OpenSSL doc indicates that unless a certificate is a CA signed cert, the "Basic Constraints" is altogether optional.  <br><br>I am planning to transition our IDP to a new IDP signing cert.  So...<div><b>My question: </b> When creating the long life, self signed IDP signing certificate, is it recommended to completely leave out "Basic Constraints"?    Or set it to CA:FALSE ?<br><br>What would be the best practice for this?<br>If this is in the wiki somewhere, please point me to it!!<br><br>Joanne<br><br>---<br><br>Joanne Schwendner<br>Identity Services<br>Office of Information Technology<br>Brown University<br><input name="virtru-metadata" type="hidden" value="{"email-policy":{"disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"expandedWatermarking":false,"expires":false,"sms":false,"expirationNum":1,"expirationUnit":"days","isManaged":false,"persistentProtection":false},"attachments":{},"compose-id":"3","compose-window":{"secure":false}}"><div><br></div></div></div>