12 database = $dir/${ENV::CA_NAME}-index.txt
14 serial = $dir/${ENV::CA_NAME}-serial
15 certificate = $dir/${ENV::CA_NAME}.pem
16 private_key = $dir/${ENV::CA_NAME}.key
21 policy = policy_anything
23 copy_extensions = copy
26 basicConstraints = critical, CA:false
27 extendedKeyUsage = serverAuth, clientAuth
28 certificatePolicies = 1.2.3.4
31 basicConstraints = critical, CA:true
32 keyUsage = critical, digitalSignature, keyCertSign, cRLSign
35 basicConstraints = critical, CA:true
36 keyUsage = critical, digitalSignature, keyCertSign, cRLSign
37 policyConstraints = requireExplicitPolicy:0
38 certificatePolicies = 1.2.3.4, 1.2.3.4.5, 1.2.3.5
41 # Default signing policy
42 countryName = optional
43 stateOrProvinceName = optional
44 localityName = optional
45 organizationName = optional
46 organizationalUnitName = optional
48 emailAddress = optional
53 string_mask = utf8only
56 distinguished_name = req_env_dn
59 CN = ${ENV::COMMON_NAME}