summaryrefslogtreecommitdiff
path: root/config_files/certificate-authority/config/sign_intermediate_csr.ini
diff options
context:
space:
mode:
authorhc <hc@email.ch>2024-11-20 12:51:33 +0800
committerhc <hc@email.ch>2024-11-20 12:51:33 +0800
commit853b82126baa1e8e408a10f91053c52626ffad29 (patch)
tree2fc1de9695810681ba654aab3c2a4867aacc1ac7 /config_files/certificate-authority/config/sign_intermediate_csr.ini
parentb1f88b682624e85b4b743343dfaaeed113b69413 (diff)
working
Diffstat (limited to 'config_files/certificate-authority/config/sign_intermediate_csr.ini')
-rw-r--r--config_files/certificate-authority/config/sign_intermediate_csr.ini43
1 files changed, 43 insertions, 0 deletions
diff --git a/config_files/certificate-authority/config/sign_intermediate_csr.ini b/config_files/certificate-authority/config/sign_intermediate_csr.ini
new file mode 100644
index 0000000..09a20f7
--- /dev/null
+++ b/config_files/certificate-authority/config/sign_intermediate_csr.ini
@@ -0,0 +1,43 @@
1[ ca ]
2# `man ca`
3default_ca = CA_default
4
5[ CA_default ]
6# Directory and file locations.
7dir = /opt/certificate-authority
8certs = $dir/certs
9crl_dir = $dir/crl
10new_certs_dir = $dir/newcerts
11database = $dir/index.txt
12serial = $dir/serial
13
14# The root key and root certificate.
15private_key = pkcs11:model=PKCS%2315%20emulated;manufacturer=www.CardContact.de;serial=DENK0104964;token=SmartCard-HSM%20%28UserPIN%29;id=%BA%6C%1F%2B%2B%16%E9%7B%4F%31%B0%91%19%73%2F%C8%DF%78%3A%FD;object=root;type=private
16certificate = ../certs/root.crt
17
18# SHA-1 is deprecated, so use SHA-2 instead.
19default_md = sha512
20
21name_opt = ca_default
22cert_opt = ca_default
23default_days = 375
24preserve = no
25policy = policy_loose
26
27[ policy_loose ]
28# Allow the intermediate CA to sign a more diverse range of certificates.
29# See the POLICY FORMAT section of the `ca` man page.
30countryName = optional
31stateOrProvinceName = optional
32localityName = optional
33organizationName = optional
34organizationalUnitName = optional
35commonName = supplied
36emailAddress = optional
37
38[ v3_intermediate_ca ]
39# Extensions for a typical intermediate CA (`man x509v3_config`).
40subjectKeyIdentifier = hash
41authorityKeyIdentifier = keyid:always,issuer
42basicConstraints = critical, CA:true, pathlen:0
43keyUsage = critical, digitalSignature, cRLSign, keyCertSign