1 basicConstraints = CA:false
2 nsCertType = client, server
3 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
4 extendedKeyUsage = clientAuth, serverAuth
5 subjectKeyIdentifier = hash
6 authorityKeyIdentifier = keyid, issuer:always
7 subjectAltName = @subject_alt_name
8 issuerAltName = issuer:copy
9 crlDistributionPoints = @cdp_section