| Name | Display name | Description | Key Usage | Extended Key Usage | CA | In use | |
| server | TLS Server | Server-auth profile for TLS endpoints | digitalSignature, keyEncipherment, keyAgreement | serverAuth | - | 92 / 0 | |
| client | TLS Client | Client-auth profile | digitalSignature, keyEncipherment, dataEncipherment, keyAgreement | clientAuth | - | 14 / 0 | |
| server_client | Server & Client | Dual-use TLS | digitalSignature, keyEncipherment | serverAuth, clientAuth | - | 5 / 0 | |
| vpn | VPN Gateway | IPSec / OpenVPN endpoints | digitalSignature | serverAuth, clientAuth | - | 6 / 2 | |
| user | End User | Generic user cert | digitalSignature, keyEncipherment | clientAuth, emailProtection | - | 21 / 0 | |
| user_login | User + Smartcard logon | User cert with Windows smartcard-logon OID | digitalSignature, keyEncipherment | clientAuth, 1.3.6.1.4.1.311.20.2.2 | - | 18 / 1 | |
| smartcard_logon | Smartcard logon only | Pure smartcard-logon EKU | digitalSignature | 1.3.6.1.4.1.311.20.2.2 | - | 2 / 0 | |
| smime_sign | S/MIME signing | Mail signing | digitalSignature, nonRepudiation | emailProtection | - | 9 / 0 | |
| code_signing | Code signing | Build / release signing | digitalSignature | codeSigning | - | 4 / 1 | |
| timestamping | Time-stamping authority | TSA cert (RFC 3161) | digitalSignature | timeStamping (critical) | - | 1 / 0 | |