This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 45 · Nov 3 – 9, 2025

crypto/x509: add ExtKeyUsage.OID

Worth knowingstdlib

What changed
The proposal adds a new method ExtKeyUsage.OID() OID and a helper OIDFromASN1OID(asn1OID asn1.ObjectIdentifier) (OID, error) to the crypto/x509 package.
Production impact
The source does not say.
Try it
Inspect a certificate’s ExtKeyUsage values and call OID() to see the underlying OID.
Source
github.com/golang/go/issues/75325

Understand it, then run it

The crypto/x509 package has a type called ExtKeyUsage that represents the extended key usage (EKU) values found in a certificate. Before the change, the only way to see what EKUs a certificate had was to look at the slice of ExtKeyUsage values and the slice of unknown OIDs. The ExtKeyUsage values were just integers, so a program could not ask “what is the ASN.1 OID for this EKU?” The change adds a method ExtKeyUsage.OID() that returns the ASN.1 object identifier for a known EKU. It also adds a helper OIDFromASN1OID to create an OID from a raw ASN.1 OID. With these additions a program can now compare EKUs by their OIDs, even if the EKU is not yet supported by the Go library.

Run it now

Todaygo
// This program demonstrates that the new ExtKeyUsage.OID method is not
// available in Go 1.27.1. It simply prints a message explaining the
// current limitation.

package main

import "fmt"

func main() {
	// In Go 1.27.1 the crypto/x509 package does not expose an OID() method
	// on the ExtKeyUsage type, so we cannot retrieve the ASN.1 object
	// identifier of an extended key usage directly.
	fmt.Println("ExtKeyUsage.OID is not available in Go 1.27.1")
}

What it printed when we ran it on Go 1.27.1

ExtKeyUsage.OID is not available in Go 1.27.1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed