# certName / usage scenario?

**URL:** https://forum.syncthing.net/t/certname-usage-scenario/17647
**Category:** Support
**Created:** [November 26, 2021, 5:20pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647 "2021-11-26T17:20:57Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![LE0N](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/l/49beb7/32.png) [@LE0N](https://forum.syncthing.net/u/LE0N)
#### Post date: [November 26, 2021, 5:20pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647/1 "2021-11-26T17:20:58Z")

</div>

Hey all, I read about the certName option and have some question marks.

Does certName affects the internal generation of the cert.pem certificate?

Scenario: Installing a new instance with a pre deployed config.xml with

```
... 
    <defaults>
        <device>
          <certName>example</certName>
        </device>
    </defaults>
...

```

or is this option just for the cases where the cert file is “manually/off site” generated and placed? Thanks.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [November 26, 2021, 6:10pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647/2 "2021-11-26T18:10:52Z")

</div>

Yes. Its just for certificates generated by something else.

---

<div class="post-metadata">

### Author: ![LE0N](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/l/49beb7/32.png) [@LE0N](https://forum.syncthing.net/u/LE0N)
#### Post date: [November 27, 2021, 7:27pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647/3 "2021-11-27T19:27:05Z")

</div>

Ok, thanks.

While evaluating the manual process in creating an equivalent cert.pem I noticed following:

I’m using

```
go run $(go env GOROOT)/src/crypto/tls/generate_cert.go --host=syncthing --ecdsa-curve=P384 --duration=$((20*24*365))h

```

for the custom cert.pem.

One difference to the syncthing cert.pem is, that syncthing adds _KeyEncipherment_ to the _KeyUsage_ list.

`https://github.com/syncthing/syncthing/blob/main/lib/tlsutil/tlsutil.go#L113`

but following stanza cames from golangs lib:

`https://cs.opensource.google/go/go/+/master:src/crypto/tls/generate_cert.go;l=87`

```
// Only RSA subject keys should have the KeyEncipherment KeyUsage bits set. In
// the context of TLS this KeyUsage is particular to RSA key exchange and
// authentication.

```

Just want to mention it here for further assessment …

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [November 27, 2021, 7:44pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647/4 "2021-11-27T19:44:41Z")

</div>

Is that causing issues?

We used to use RSA keys which is probably why it’s still there.

---

<div class="post-metadata">

### Author: ![system](https://forum-uploads.syncthingcdn.net/original/2X/0/0b50e0a202b22ae6a67190759e8c868805b8ed9f.png) [@system](https://forum.syncthing.net/u/system)
#### Post date: [December 27, 2021, 7:45pm UTC](https://forum.syncthing.net/t/certname-usage-scenario/17647/5 "2021-12-27T19:45:27Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
