OptionalcheckCheck certificate revocation using CRLs
OptionalcheckCheck certificate revocation using OCSP
OptionalcheckWhether to perform signature validation
OptionalenforceWhether to enforce CA constraints and key usage
OptionalotherOther certificates available for chain building
OptionalrequiredRequired policy OIDs (if any)
OptionaltimeTolerance for time-based validations (in milliseconds)
OptionaltrustTrust anchors to use for chain validation
OptionalvalidateWhether to build and validate the full certificate chain
OptionalvalidateWhether to validate name constraints
OptionalvalidateWhether to validate certificate policies
OptionalvalidationCustom validation date (defaults to current time)
Options for certificate validation.