2 RANDFILE = /var/tmp/.rnd
14 database = $dir/certs/index.txt
15 new_certs_dir = $dir/certs
16 certificate = $dir/ca/cacert.pem
17 serial = $dir/certs/serial
18 crl = $dir/crls/cacrl.pem
19 private_key = $dir/private/cakey.pem
20 RANDFILE = $dir/tmp/.rand
21 x509_extensions = usr_cert
30 countryName = optional
31 stateOrProvinceName = optional
32 organizationName = optional
33 organizationalUnitName = optional
35 emailAddress = optional
39 default_keyfile = privkey.pem
40 distinguished_name = req_distinguished_name
41 attributes = req_attributes
42 x509_extensions = v3_ca
45 [ req_distinguished_name ]
46 countryName = Country Name (2 letter code)
47 countryName_default = DE
51 stateOrProvinceName = State or Province Name (full name)
52 stateOrProvinceName_default =
54 localityName = Locality Name (eg, city)
55 #localityName_default =
57 0.organizationName = Organization Name (eg, company)
58 0.organizationName_default = IPFire
60 organizationalUnitName = Organizational Unit Name (eg, section)
61 #organizationalUnitName_default =
63 commonName = Common Name (eg, your name or your server\'s hostname)
66 emailAddress = Email Address
70 challengePassword = A challenge password
71 challengePassword_min = 4
72 challengePassword_max = 20
73 unstructuredName = An optional company name
76 basicConstraints=CA:FALSE
77 nsComment = "OpenSSL Generated Certificate"
78 subjectKeyIdentifier=hash
79 authorityKeyIdentifier=keyid,issuer:always
82 basicConstraints = CA:FALSE
83 keyUsage = nonRepudiation, digitalSignature, keyEncipherment
86 subjectKeyIdentifier=hash
87 authorityKeyIdentifier=keyid:always,issuer:always
88 basicConstraints = CA:true
91 authorityKeyIdentifier=keyid:always,issuer:always