--- /dev/null
+basicConstraints = CA:false
+nsCertType = client, server
+keyUsage = nonRepudiation, digitalSignature, keyEncipherment
+extendedKeyUsage = clientAuth, serverAuth
+nsComment = "%(cn)s"
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid, issuer:always
+subjectAltName = @subject_alt_name
+issuerAltName = issuer:copy
+nsCaRevocationUrl = %(crl_url)s
+nsRevocationUrl = %(crl_url)s
+crlDistributionPoints = @cdp_section
+
+[ subject_alt_name ]
+%(alt_names)s
+email = copy
+
+[ cdp_section ]
+URI.1 = %(crl_url)s