Remove building with NOCRYPTO option
[minix.git] / crypto / external / bsd / heimdal / dist / lib / hx509 / data / openssl.cnf
bloba6054009d955a1c5511b18cef5d2c5c4c0f47ad4
1 oid_section             = new_oids
3 [new_oids]
4 pkkdcekuoid = 1.3.6.1.5.2.3.5
6 [ca]
8 default_ca = user
10 [usr]
11 database        = index.txt
12 serial          = serial
13 x509_extensions = usr_cert
14 default_md=sha1
15 policy          = policy_match
16 email_in_dn     = no
17 certs           = .
19 [ocsp]
20 database        = index.txt
21 serial          = serial
22 x509_extensions = ocsp_cert
23 default_md=sha1
24 policy          = policy_match
25 email_in_dn     = no
26 certs           = .
28 [usr_ke]
29 database        = index.txt
30 serial          = serial
31 x509_extensions = usr_cert_ke
32 default_md=sha1
33 policy          = policy_match
34 email_in_dn     = no
35 certs           = .
37 [usr_ds]
38 database        = index.txt
39 serial          = serial
40 x509_extensions = usr_cert_ds
41 default_md=sha1
42 policy          = policy_match
43 email_in_dn     = no
44 certs           = .
46 [pkinit_client]
47 database        = index.txt
48 serial          = serial
49 x509_extensions = pkinit_client_cert
50 default_md=sha1
51 policy          = policy_match
52 email_in_dn     = no
53 certs           = .
55 [pkinit_kdc]
56 database        = index.txt
57 serial          = serial
58 x509_extensions = pkinit_kdc_cert
59 default_md=sha1
60 policy          = policy_match
61 email_in_dn     = no
62 certs           = .
64 [https]
65 database        = index.txt
66 serial          = serial
67 x509_extensions = https_cert
68 default_md=sha1
69 policy          = policy_match
70 email_in_dn     = no
71 certs           = .
73 [subca]
74 database        = index.txt
75 serial          = serial
76 x509_extensions = v3_ca
77 default_md=sha1
78 policy          = policy_match
79 email_in_dn     = no
80 certs           = .
83 [req]
84 distinguished_name      = req_distinguished_name
85 x509_extensions         = v3_ca # The extentions to add to the self signed cert
87 string_mask = utf8only
89 [v3_ca]
91 subjectKeyIdentifier=hash
92 authorityKeyIdentifier=keyid:always,issuer:always
93 basicConstraints = CA:true
94 keyUsage = cRLSign, keyCertSign, keyEncipherment, nonRepudiation, digitalSignature
96 [usr_cert]
97 basicConstraints=CA:FALSE
98 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
99 subjectKeyIdentifier    = hash
101 [usr_cert_ke]
102 basicConstraints=CA:FALSE
103 keyUsage = nonRepudiation, keyEncipherment
104 subjectKeyIdentifier    = hash
106 [proxy_cert]
107 basicConstraints=CA:FALSE
108 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
109 subjectKeyIdentifier    = hash
110 proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:0,policy:text:foo
112 [pkinitc_principals] 
113 princ1 = GeneralString:bar
115 [pkinitc_principal_seq] 
116 name_type = EXP:0,INTEGER:1 
117 name_string = EXP:1,SEQUENCE:pkinitc_principals
119 [pkinitc_princ_name] 
120 realm = EXP:0,GeneralString:TEST.H5L.SE
121 principal_name = EXP:1,SEQUENCE:pkinitc_principal_seq
123 [pkinit_client_cert]
124 basicConstraints=CA:FALSE
125 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
126 subjectKeyIdentifier    = hash
127 subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:pkinitc_princ_name
129 [https_cert]
130 basicConstraints=CA:FALSE
131 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
132 #extendedKeyUsage = https-server XXX
133 subjectKeyIdentifier    = hash
135 [pkinit_kdc_cert]
136 basicConstraints=CA:FALSE
137 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
138 extendedKeyUsage = pkkdcekuoid
139 subjectKeyIdentifier    = hash
140 subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:pkinitkdc_princ_name 
142 [pkinitkdc_princ_name] 
143 realm = EXP:0,GeneralString:TEST.H5L.SE
144 principal_name = EXP:1,SEQUENCE:pkinitkdc_principal_seq
146 [pkinitkdc_principal_seq] 
147 name_type = EXP:0,INTEGER:1 
148 name_string = EXP:1,SEQUENCE:pkinitkdc_principals
150 [pkinitkdc_principals] 
151 princ1 = GeneralString:krbtgt
152 princ2 = GeneralString:TEST.H5L.SE
154 [proxy10_cert]
155 basicConstraints=CA:FALSE
156 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
157 subjectKeyIdentifier    = hash
158 proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:10,policy:text:foo
160 [usr_cert_ds]
161 basicConstraints=CA:FALSE
162 keyUsage = nonRepudiation, digitalSignature
163 subjectKeyIdentifier    = hash
165 [ocsp_cert]
166 basicConstraints=CA:FALSE
167 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
168 # ocsp-nocheck and kp-OCSPSigning
169 extendedKeyUsage        = 1.3.6.1.5.5.7.48.1.5, 1.3.6.1.5.5.7.3.9
170 subjectKeyIdentifier    = hash
172 [req_distinguished_name]
173 countryName                     = Country Name (2 letter code)
174 countryName_default             = SE
175 countryName_min                 = 2
176 countryName_max                 = 2
178 organizationalName              = Organizational Unit Name (eg, section)
180 commonName                      = Common Name (eg, YOUR name)
181 commonName_max                  = 64
183 #[req_attributes]
184 #challengePassword              = A challenge password
185 #challengePassword_min          = 4
186 #challengePassword_max          = 20
188 [policy_match]
189 countryName             = match
190 commonName              = supplied