x509v3.cnf 1.2 KB

1234567891011121314151617181920212223242526272829303132333435
  1. CERTPATHLEN = 1
  2. CERTUSAGE = digitalSignature,keyCertSign,cRLSign
  3. EXTCERTUSAGE = serverAuth,clientAuth
  4. CADB = index.txt
  5. CASERIAL = serial.txt
  6. NSCERTTYPE = server,client
  7. [ x509v3_extensions ]
  8. nsCertType = 0x40
  9. [ x509v3_CA ]
  10. basicConstraints = critical,CA:true,pathlen:$ENV::CERTPATHLEN
  11. keyUsage = $ENV::CERTUSAGE
  12. [ ca ]
  13. default_ca = CA_default
  14. [ CA_sign_policy ]
  15. countryName = optional
  16. stateOrProvinceName = optional
  17. localityName = optional
  18. organizationName = optional
  19. organizationalUnitName = optional
  20. commonName = supplied
  21. emailAddress = optional
  22. [ CA_default ]
  23. database = $ENV::CADB
  24. serial = $ENV::CASERIAL
  25. default_md = sha256
  26. default_days = 3650
  27. default_crl_days = 3650
  28. unique_subject = yes
  29. email_in_dn = yes
  30. policy = CA_sign_policy