Knowledge Base

How to verify Enhanced Key Usage (EKU) in a certificate

Overview

By the end of this article, you will be able to open a certificate file on a Windows computer, read its Enhanced Key Usage (EKU) values, and confirm whether the certificate supports the authentication use case you need. The article first defines Enhanced Key Usage and the Object Identifier (OID) numbers that represent each usage value, then lists the prerequisites, walks through the verification steps in the Windows Certificate Viewer, and shows how to confirm success. It closes with troubleshooting guidance for certificates that do not display the expected values.

What is Enhanced Key Usage (EKU)?

Enhanced Key Usage (EKU) is a certificate field that lists the specific purposes a certificate is allowed to be used for, such as authenticating a server or authenticating a client. Each purpose is recorded as an Object Identifier (OID), which is a standardized numeric code. A certificate used for mutual authentication normally lists two values: Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2). If a required purpose is not listed in the Enhanced Key Usage field, applications that check the field may reject the certificate.

Prerequisites

  • The certificate file is downloaded and saved on your computer.
  • You are using a Windows device with the built-in Certificate Viewer, which opens .cer and .crt files when you double-click them.

Steps to verify Enhanced Key Usage

The steps below open the certificate file in the Windows Certificate Viewer and display the Enhanced Key Usage (EKU) field.

  1. Locate the downloaded certificate file on your computer.
  2. Double-click the certificate file. The Windows Certificate Viewer opens.
  3. Select the Details tab.
  4. In the field list, select Enhanced Key Usage.
  5. Read the values shown in the lower pane of the window and compare them with the values your application requires.

Reference screenshot

The screenshot below shows the Windows Certificate Viewer with the Details tab open, the Enhanced Key Usage field selected in the field list, and the lower pane displaying Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2).

 

 Figure 1: Windows Certificate Viewer Details tab with Enhanced Key Usage selected, showing Server Authentication and Client Authentication values

How to verify success

The check is successful when the Enhanced Key Usage (EKU) field of the certificate displays both of the following values:

Usage valueObject Identifier (OID)
Server Authentication1.3.6.1.5.5.7.3.1
Client Authentication1.3.6.1.5.5.7.3.2

If both values are listed, the certificate supports server and client authentication.

Troubleshooting

Issue: Enhanced Key Usage does not appear in the field list.

Cause: The certificate was issued without an Enhanced Key Usage extension, so no usage restriction is recorded.

Solution: Contact your certificate provider and request a reissued certificate that includes the required Enhanced Key Usage values.

Issue: Only Server Authentication is listed, and Client Authentication is missing.

Cause: The certificate was ordered under a product or profile that supports server authentication only.

Solution: Confirm which certificate product supports both usages, then request a reissue under the correct product before configuring mutual authentication.

Frequently asked questions

What is Enhanced Key Usage in a certificate?

Enhanced Key Usage (EKU) is a certificate field listing the specific purposes the certificate may be used for, such as Server Authentication or Client Authentication. Each purpose is recorded as an Object Identifier (OID) number.

How do I check Enhanced Key Usage on Windows?

Double-click the certificate file to open the Windows Certificate Viewer, select the Details tab, and select Enhanced Key Usage in the field list. The values appear in the lower pane.

What should I do if Client Authentication is missing from my certificate?

Contact your certificate provider or support team and request a reissued certificate that includes Client Authentication (1.3.6.1.5.5.7.3.2). A certificate without that value will be rejected by applications that require client authentication.

Can I verify Enhanced Key Usage without a Windows device?

Yes. On systems without the Windows Certificate Viewer, the same field can be read using a command-line certificate tool that prints the certificate's extensions. The usage values and OID numbers shown are identical.

Similar questions

  • How do I check what a certificate can be used for?
  • What are the steps to view certificate details on Windows?
  • Enhanced Key Usage OID values
  • How do I confirm a certificate supports client authentication?
  • Why does my certificate fail mutual authentication?

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today