CACertificatesWithConstraints

TLS certificates that should be trusted by Samsung Browser for server authentication with constraints

Supported on:

  • Chrome (Windows) since version 132

Description:

A list of TLS certificates that should be trusted by Samsung Browser for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.
Certificates should be base64-encoded. At least one constraint must be specified for each certificate.

Supported features:

  • Applied to browser without restart. Note that some ongoing tasks may not be affected.
  • Applied at Samsung Browser profile level.

Data type:

Dictionary
Windows:REG_SZ

Windows registry location:

Software\Policies\Samsung\Internet\CACertificatesWithConstraints

Schema:

{
  "items": {
    "properties": {
      "certificate": {
        "type": "string"
      },
      "constraints": {
        "properties": {
          "permitted_cidrs": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "permitted_dns_names": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      }
    },
    "type": "object"
  },
  "type": "array"
}

Example value:

[
  {
    "certificate": "MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X",
    "constraints": {
      "permitted_dns_names": [
        "example.org"
      ],
      "permitted_cidrs": [
        "10.1.1.0/24"
      ]
    }
  }
]

More policies under Certificate management settings: