1 basicConstraints        = CA:false
 
   2 nsCertType              = client, server
 
   3 keyUsage                = nonRepudiation, digitalSignature, keyEncipherment
 
   4 extendedKeyUsage        = clientAuth, serverAuth
 
   5 subjectKeyIdentifier    = hash
 
   6 authorityKeyIdentifier  = keyid, issuer:always
 
   7 subjectAltName          = @subject_alt_name
 
   8 issuerAltName           = issuer:copy
 
   9 crlDistributionPoints   = @cdp_section