When clicking on the templates "Sub CA" and "Root CA" the fields in the certificate profile are not updated accordingly. This is annoying at best, fatal at worst (although one should be really careful about setting parameters for CAs, an unexcepted behavioural change may potentially cause havoc, especially when you only after the key ceremony realise that your newly generated CA certificate has Extended Key Usage = Client Authentication).
The following fields should be updated when changing from End Entity to Sub CA/Root CA
Validity or end date of the certificate 24y
Key usage: CRL Sign, Key certificate sign, Digital signature
Extended Key Usage: Disable