1 RANDFILE = ${ENV::CAROOT}/.random
4 default_ca = CA_default
9 certs = $dir/public/certs
10 crl_dir = $dir/public/crl
11 crl = $dir/public/crl.pem
12 crlnumber = $dir/crlnumber
15 new_certs_dir = $dir/newcerts
16 certificate = $dir/public/ca.pem
17 private_key = $dir/private/ca.key
18 x509_extensions = certificate_extensions
20 default_days = %(default_days)s
27 countryName = supplied
28 organizationName = supplied
29 organizationalUnitName = optional
31 emailAddress = optional
34 countryName = optional
35 organizationName = optional
36 organizationalUnitName = optional
38 emailAddress = optional
41 default_bits = %(bits)s
43 distinguished_name = req_distinguished_name
44 attributes = req_attributes
45 x509_extensions = v3_ca
48 [ req_distinguished_name ]
49 countryName = Country Name
50 countryName_default = "%(country)s"
53 0.organizationName = Organization Name
54 0.organizationName_default = "%(org)s"
55 organizationalUnitName = Organizational Unit Name
56 organizationalUnitName_default = "%(ou)s"
57 commonName = Common Name
59 commonName_default = "%(cn)s"
60 SET-ex3 = SET extension number 3
64 [ certificate_extensions ]
67 subjectKeyIdentifier = hash
68 authorityKeyIdentifier = keyid:always,issuer:always
69 basicConstraints = critical, CA:true
70 keyUsage = cRLSign, keyCertSign
71 nsCertType = sslCA, emailCA, objCA
73 subjectAltName = @ca_alt_name
74 issuerAltName = issuer:copy