basicConstraints        = CA:false
-nsCertType              = client, server
+nsCertType              = %(usage)s
 keyUsage                = nonRepudiation, digitalSignature, keyEncipherment
 extendedKeyUsage        = clientAuth, serverAuth
-nsComment               = "%(cn)s"
 subjectKeyIdentifier    = hash
 authorityKeyIdentifier  = keyid, issuer:always
 subjectAltName          = @subject_alt_name