summaryrefslogtreecommitdiff
path: root/config_files/certificate-authority/config/sign_server_and_client_csrs.ini
diff options
context:
space:
mode:
authorhc <hc@email.ch>2024-11-20 12:51:33 +0800
committerhc <hc@email.ch>2024-11-20 12:51:33 +0800
commit853b82126baa1e8e408a10f91053c52626ffad29 (patch)
tree2fc1de9695810681ba654aab3c2a4867aacc1ac7 /config_files/certificate-authority/config/sign_server_and_client_csrs.ini
parentb1f88b682624e85b4b743343dfaaeed113b69413 (diff)
working
Diffstat (limited to 'config_files/certificate-authority/config/sign_server_and_client_csrs.ini')
-rw-r--r--config_files/certificate-authority/config/sign_server_and_client_csrs.ini45
1 files changed, 45 insertions, 0 deletions
diff --git a/config_files/certificate-authority/config/sign_server_and_client_csrs.ini b/config_files/certificate-authority/config/sign_server_and_client_csrs.ini
new file mode 100644
index 0000000..0cffc13
--- /dev/null
+++ b/config_files/certificate-authority/config/sign_server_and_client_csrs.ini
@@ -0,0 +1,45 @@
1[ ca ]
2default_ca = CA_default
3
4[ CA_default ]
5dir = /opt/certificate-authority/intermediate
6certs = $dir/certs
7crl_dir = $dir/crl
8new_certs_dir = $dir/newcerts
9database = $dir/index.txt
10serial = $dir/serial
11private_key = pkcs11:model=PKCS%2315%20emulated;manufacturer=www.CardContact.de;serial=DENK0104964;token=SmartCard-HSM%20%28UserPIN%29;id=%D6%0E%28%C8%ED%2B%D5%FF%87%6B%88%06%4F%5B%70%1A%E5%F7%B4%99;object=intermediate;type=private
12certificate = $dir/certs/intermediate.crt
13default_md = sha512
14name_opt = ca_default
15cert_opt = ca_default
16default_days = 375
17preserve = no
18policy = policy_loose
19
20[ policy_loose ]
21countryName = optional
22stateOrProvinceName = optional
23localityName = optional
24organizationName = optional
25organizationalUnitName = optional
26commonName = supplied
27emailAddress = optional
28
29[ server_cert ]
30basicConstraints = CA:FALSE
31nsCertType = server
32nsComment = "OpenSSL Generated Server Certificate"
33subjectKeyIdentifier = hash
34authorityKeyIdentifier = keyid,issuer:always
35keyUsage = critical, digitalSignature, keyEncipherment
36extendedKeyUsage = serverAuth
37
38[ client_cert ]
39basicConstraints = CA:FALSE
40nsCertType = client
41nsComment = "OpenSSL Generated Client Certificate"
42subjectKeyIdentifier = hash
43authorityKeyIdentifier = keyid,issuer:always
44keyUsage = critical, digitalSignature
45extendedKeyUsage = clientAuth