certificate field
Key usage
What it means
What the key is allowed to do at the cryptographic level: sign data (digitalSignature), encrypt keys (keyEncipherment), sign other certificates (keyCertSign), sign revocation lists (cRLSign).
Why it matters
A certificate used outside its key usage is rejected by strict clients. keyCertSign on a certificate is what makes it a CA — see Basic Constraints.
See this field on your own certificate
Drop or paste any certificate into the decoder — every field explained, nothing uploaded.
Open the certificate decoder →