{
    "profiles": [
        {
            "name": "mtls-service",
            "display_name": "Mutual TLS Service",
            "description": "Private service identity for mutual TLS authentication.",
            "requirements": {
                "name": "mtls-service",
                "display_name": "Mutual TLS Service",
                "certificate_kind": "end_entity",
                "description": "Private service identity for mutual TLS authentication.",
                "trust_class": "AMMONITRIX_PRIVATE_TRUST",
                "external_authority_required": false,
                "public_request_allowed": true,
                "validity": {
                    "days": 365,
                    "renew_before_days": 30
                },
                "key": {
                    "allowed": [
                        "RSA-3072",
                        "P-256",
                        "P-384"
                    ],
                    "default": "P-384",
                    "exportable": false,
                    "hsm": "recommended"
                },
                "subject": {
                    "required": [
                        "CN",
                        "O"
                    ],
                    "allowed": [
                        "CN",
                        "O",
                        "OU",
                        "C"
                    ]
                },
                "san": {
                    "required": true,
                    "allowed": [
                        "DNS",
                        "IP",
                        "URI"
                    ]
                },
                "extensions": {
                    "basic_constraints": {
                        "ca": false,
                        "critical": true
                    },
                    "key_usage": [
                        "digitalSignature"
                    ],
                    "extended_key_usage": [
                        "serverAuth",
                        "clientAuth"
                    ],
                    "aia": true,
                    "crl_distribution_points": true
                },
                "approval": {
                    "roles": [
                        "certificate_approver"
                    ],
                    "minimum": 1
                }
            }
        },
        {
            "name": "tls-client",
            "display_name": "TLS Client",
            "description": "Private-trust client authentication identity.",
            "requirements": {
                "name": "tls-client",
                "display_name": "TLS Client",
                "certificate_kind": "end_entity",
                "description": "Private-trust client authentication identity.",
                "trust_class": "AMMONITRIX_PRIVATE_TRUST",
                "external_authority_required": false,
                "public_request_allowed": true,
                "validity": {
                    "days": 365,
                    "renew_before_days": 30
                },
                "key": {
                    "allowed": [
                        "RSA-3072",
                        "P-256",
                        "P-384"
                    ],
                    "default": "P-256",
                    "exportable": false,
                    "hsm": "optional"
                },
                "subject": {
                    "required": [
                        "CN",
                        "O"
                    ],
                    "allowed": [
                        "CN",
                        "O",
                        "OU",
                        "C"
                    ]
                },
                "san": {
                    "required": false,
                    "allowed": [
                        "DNS",
                        "RFC822",
                        "URI",
                        "UPN"
                    ]
                },
                "extensions": {
                    "basic_constraints": {
                        "ca": false,
                        "critical": true
                    },
                    "key_usage": [
                        "digitalSignature"
                    ],
                    "extended_key_usage": [
                        "clientAuth"
                    ],
                    "aia": true,
                    "crl_distribution_points": true
                },
                "approval": {
                    "roles": [
                        "certificate_approver"
                    ],
                    "minimum": 1
                }
            }
        },
        {
            "name": "tls-server",
            "display_name": "TLS Server",
            "description": "Private-trust HTTP/TLS server identity.",
            "requirements": {
                "name": "tls-server",
                "display_name": "TLS Server",
                "certificate_kind": "end_entity",
                "description": "Private-trust HTTP/TLS server identity.",
                "trust_class": "AMMONITRIX_PRIVATE_TRUST",
                "external_authority_required": false,
                "public_request_allowed": true,
                "validity": {
                    "days": 397,
                    "renew_before_days": 30
                },
                "key": {
                    "allowed": [
                        "RSA-3072",
                        "RSA-4096",
                        "P-256",
                        "P-384"
                    ],
                    "default": "P-384",
                    "exportable": false,
                    "hsm": "recommended"
                },
                "subject": {
                    "required": [
                        "CN",
                        "O"
                    ],
                    "allowed": [
                        "CN",
                        "O",
                        "OU",
                        "C",
                        "ST",
                        "L"
                    ]
                },
                "san": {
                    "required": true,
                    "allowed": [
                        "DNS",
                        "IP"
                    ]
                },
                "extensions": {
                    "basic_constraints": {
                        "ca": false,
                        "critical": true
                    },
                    "key_usage": [
                        "digitalSignature"
                    ],
                    "extended_key_usage": [
                        "serverAuth"
                    ],
                    "aia": true,
                    "crl_distribution_points": true
                },
                "approval": {
                    "roles": [
                        "certificate_approver"
                    ],
                    "minimum": 1
                }
            }
        }
    ]
}
