]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/ssl/openssl.cnf
Merge branch 'next'
[people/pmueller/ipfire-2.x.git] / config / ssl / openssl.cnf
CommitLineData
cd1a2927 1HOME = .
cd1a2927
MT
2oid_section = new_oids
3
4[ new_oids ]
5
6[ ca ]
33a31f1a 7default_ca = IPFire
cd1a2927 8
1ce6d696 9[ IPFire ]
33a31f1a 10dir = /var/ipfire
cd1a2927 11certs = $dir/certs
e3a8510a 12crl_dir = $dir/crls
cd1a2927
MT
13database = $dir/certs/index.txt
14new_certs_dir = $dir/certs
15certificate = $dir/ca/cacert.pem
16serial = $dir/certs/serial
17crl = $dir/crls/cacrl.pem
18private_key = $dir/private/cakey.pem
cd1a2927
MT
19x509_extensions = usr_cert
20default_days = 999999
21default_crl_days= 30
3847730c 22default_md = sha256
cd1a2927
MT
23preserve = no
24policy = policy_match
25email_in_dn = no
9f010115 26copy_extensions = copyall
cd1a2927
MT
27
28[ policy_match ]
29countryName = optional
30stateOrProvinceName = optional
31organizationName = optional
32organizationalUnitName = optional
33commonName = supplied
34emailAddress = optional
35
36[ req ]
3847730c 37default_bits = 2048
cd1a2927
MT
38default_keyfile = privkey.pem
39distinguished_name = req_distinguished_name
40attributes = req_attributes
41x509_extensions = v3_ca
42string_mask = nombstr
43
44[ req_distinguished_name ]
45countryName = Country Name (2 letter code)
e3a8510a
MT
46countryName_default = DE
47countryName_min = 2
48countryName_max = 2
cd1a2927
MT
49
50stateOrProvinceName = State or Province Name (full name)
51stateOrProvinceName_default =
52
53localityName = Locality Name (eg, city)
54#localityName_default =
55
560.organizationName = Organization Name (eg, company)
e3a8510a 570.organizationName_default = IPFire
cd1a2927
MT
58
59organizationalUnitName = Organizational Unit Name (eg, section)
60#organizationalUnitName_default =
61
62commonName = Common Name (eg, your name or your server\'s hostname)
e3a8510a 63commonName_max = 64
cd1a2927
MT
64
65emailAddress = Email Address
66emailAddress_max = 40
67
68[ req_attributes ]
69challengePassword = A challenge password
e3a8510a
MT
70challengePassword_min = 4
71challengePassword_max = 20
cd1a2927
MT
72unstructuredName = An optional company name
73
74[ usr_cert ]
75basicConstraints=CA:FALSE
76nsComment = "OpenSSL Generated Certificate"
77subjectKeyIdentifier=hash
78authorityKeyIdentifier=keyid,issuer:always
79
80[ v3_req ]
81basicConstraints = CA:FALSE
82keyUsage = nonRepudiation, digitalSignature, keyEncipherment
83
84[ v3_ca ]
85subjectKeyIdentifier=hash
86authorityKeyIdentifier=keyid:always,issuer:always
87basicConstraints = CA:true
88
89[ crl_ext ]
90authorityKeyIdentifier=keyid:always,issuer:always
91
92[ engine ]
93default = openssl