If it only have digital signature flag, iOS client will complain error like: "EKU not found", "CERTIFICATE_ERROR_VERIFY_KEYUSAGE_FAILED:The certificate did not contain the required Key Usages", after added the other flags, no more errors like these. On Wed, Dec 11, 2013 at 3:41 PM, Nikos Mavrogiannopoulos <nmav at gnutls.org> wrote: > digital signature flag