4 pkkdcekuoid = 1.3.6.1.5.2.3.5
13 x509_extensions = usr_cert
22 x509_extensions = ocsp_cert
31 x509_extensions = usr_cert_ke
40 x509_extensions = usr_cert_ds
49 x509_extensions = pkinit_client_cert
58 x509_extensions = pkinit_kdc_cert
67 x509_extensions = https_cert
76 x509_extensions = v3_ca
84 distinguished_name = req_distinguished_name
85 x509_extensions = v3_ca # The extentions to add to the self signed cert
87 string_mask = utf8only
91 subjectKeyIdentifier=hash
92 authorityKeyIdentifier=keyid:always,issuer:always
93 basicConstraints = CA:true
94 keyUsage = cRLSign, keyCertSign, keyEncipherment, nonRepudiation, digitalSignature
97 basicConstraints=CA:FALSE
98 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
99 subjectKeyIdentifier = hash
102 basicConstraints=CA:FALSE
103 keyUsage = nonRepudiation, keyEncipherment
104 subjectKeyIdentifier = hash
107 basicConstraints=CA:FALSE
108 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
109 subjectKeyIdentifier = hash
110 proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:0,policy:text:foo
113 princ1 = GeneralString:bar
115 [pkinitc_principal_seq]
116 name_type = EXP:0,INTEGER:1
117 name_string = EXP:1,SEQUENCE:pkinitc_principals
120 realm = EXP:0,GeneralString:TEST.H5L.SE
121 principal_name = EXP:1,SEQUENCE:pkinitc_principal_seq
124 basicConstraints=CA:FALSE
125 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
126 subjectKeyIdentifier = hash
127 subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:pkinitc_princ_name
130 basicConstraints=CA:FALSE
131 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
132 #extendedKeyUsage = https-server XXX
133 subjectKeyIdentifier = hash
136 basicConstraints=CA:FALSE
137 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
138 extendedKeyUsage = pkkdcekuoid
139 subjectKeyIdentifier = hash
140 subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:pkinitkdc_princ_name
142 [pkinitkdc_princ_name]
143 realm = EXP:0,GeneralString:TEST.H5L.SE
144 principal_name = EXP:1,SEQUENCE:pkinitkdc_principal_seq
146 [pkinitkdc_principal_seq]
147 name_type = EXP:0,INTEGER:1
148 name_string = EXP:1,SEQUENCE:pkinitkdc_principals
150 [pkinitkdc_principals]
151 princ1 = GeneralString:krbtgt
152 princ2 = GeneralString:TEST.H5L.SE
155 basicConstraints=CA:FALSE
156 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
157 subjectKeyIdentifier = hash
158 proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:10,policy:text:foo
161 basicConstraints=CA:FALSE
162 keyUsage = nonRepudiation, digitalSignature
163 subjectKeyIdentifier = hash
166 basicConstraints=CA:FALSE
167 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
168 # ocsp-nocheck and kp-OCSPSigning
169 extendedKeyUsage = 1.3.6.1.5.5.7.48.1.5, 1.3.6.1.5.5.7.3.9
170 subjectKeyIdentifier = hash
172 [req_distinguished_name]
173 countryName = Country Name (2 letter code)
174 countryName_default = SE
178 organizationalName = Organizational Unit Name (eg, section)
180 commonName = Common Name (eg, YOUR name)
184 #challengePassword = A challenge password
185 #challengePassword_min = 4
186 #challengePassword_max = 20
190 commonName = supplied