3 AIA_URL=http://aia-test.invalid
13 database = $dir/${ENV::CA_NAME}-index.txt
15 serial = $dir/${ENV::CA_NAME}-serial
16 certificate = $dir/${ENV::CA_NAME}.pem
17 private_key = $dir/${ENV::CA_NAME}.key
22 policy = policy_anything
24 copy_extensions = copy
27 basicConstraints = critical, CA:false
28 extendedKeyUsage = serverAuth, clientAuth
29 authorityInfoAccess = caIssuers;URI:${ENV::AIA_URL}
32 basicConstraints = critical, CA:true
33 keyUsage = critical, keyCertSign, cRLSign
36 # Default signing policy
37 countryName = optional
38 stateOrProvinceName = optional
39 localityName = optional
40 organizationName = optional
41 organizationalUnitName = optional
43 emailAddress = optional
48 string_mask = utf8only
51 distinguished_name = req_env_dn
54 CN = ${ENV::CA_COMMON_NAME}