ca.conf 1.1 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647
  1. [ca]
  2. default_ca = CA_default
  3. [CA_default]
  4. database = dir/index.txt
  5. serial = dir/serial.txt
  6. new_certs_dir = ./certdir
  7. private_key = rca-private-key.pem
  8. default_days = 365
  9. certificate = rca-signed-cert.pem
  10. default_md = sha256
  11. policy = policy_any
  12. email_in_dn = no
  13. [ICA_default]
  14. database = idir/index.txt
  15. serial = idir/serial.txt
  16. new_certs_dir = ./icertdir
  17. private_key = ica-private-key.pem
  18. default_days = 365
  19. certificate = ica-signed-cert.pem
  20. default_md = sha256
  21. policy = policy_any
  22. email_in_dn = no
  23. [policy_any]
  24. countryName = supplied
  25. stateOrProvinceName = optional
  26. organizationName = optional
  27. organizationalUnitName = optional
  28. commonName = optional
  29. emailAddress = optional
  30. [ v3_ca ]
  31. subjectKeyIdentifier = hash
  32. authorityKeyIdentifier = keyid:always,issuer
  33. basicConstraints = critical, CA:true
  34. keyUsage = critical, keyCertSign, cRLSign
  35. [ v3_intermediate_ca ]
  36. subjectKeyIdentifier = hash
  37. authorityKeyIdentifier = keyid:always,issuer
  38. basicConstraints = critical, CA:true, pathlen:0
  39. keyUsage = critical, digitalSignature, cRLSign, keyCertSign