3.1.2.4.2.2.1.2 Certificate.Template.pKIExtendedKeyUsage
The client MUST create the extended key usage extension with the keyPurposeId as specified for the Certificate.Template.pKIExtendedKeyUsage datum (section 3.1.2.4.2.2.1.2). Specifications on this extension are in [RFC3280] section 4.2.1.13.
This extension MUST be added as a request attribute to the certificate request, as specified in section 2.2.2.7.7.