Control ID: CA-CRYPTO-003
Control Name: CA Certificate Extended Key Usage Validation
Severity: High
Status: Success
Certificate Authority: Securetron-Lab-ROOT-CA
Execution Time: 2025-10-15 22:43:13
Duration: 00:00:00.0096253

Expected Result:
CA certificate should not contain prohibited Extended Key Usages

Evidence:
CA Certificate Details:
  Subject: CN=Securetron-Lab-ROOT-CA, DC=securetron-lab, DC=local
  Issuer: CN=Securetron-Lab-ROOT-CA, DC=securetron-lab, DC=local
  Thumbprint: D227EAC507616D5A948EB059765EAC07AF9E653B
  Valid From: 2025-09-20
  Valid To: 2045-09-20
  Certificate Source: Audit-Results directory

Extended Key Usages Found:
  No Extended Key Usages found

Prohibited EKUs Checked (from parameters.json):
  Server Authentication, Client Authentication, Code Signing, Email Protection, Time Stamping, OCSP Signing

No prohibited EKUs detected.
  Compliant: YES

Certificate reused from CA-CRYPTO-001


Recommendation:
CA certificate does not contain prohibited Extended Key Usages.
