]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/ssl/openssl.cnf
Ich hab mal ein bisschen die Arbeit vom Cuebernommen :D
[people/pmueller/ipfire-2.x.git] / config / ssl / openssl.cnf
CommitLineData
cd1a2927
MT
1HOME = .
2RANDFILE = /var/tmp/.rnd
3oid_section = new_oids
4
5[ new_oids ]
6
7[ ca ]
33a31f1a 8default_ca = IPFire
cd1a2927 9
1ce6d696 10[ IPFire ]
33a31f1a 11dir = /var/ipfire
cd1a2927 12certs = $dir/certs
e3a8510a 13crl_dir = $dir/crls
cd1a2927
MT
14database = $dir/certs/index.txt
15new_certs_dir = $dir/certs
16certificate = $dir/ca/cacert.pem
17serial = $dir/certs/serial
18crl = $dir/crls/cacrl.pem
19private_key = $dir/private/cakey.pem
20RANDFILE = $dir/tmp/.rand
21x509_extensions = usr_cert
22default_days = 999999
23default_crl_days= 30
24default_md = md5
25preserve = no
26policy = policy_match
27email_in_dn = no
28
29[ policy_match ]
30countryName = optional
31stateOrProvinceName = optional
32organizationName = optional
33organizationalUnitName = optional
34commonName = supplied
35emailAddress = optional
36
37[ req ]
38default_bits = 1024
39default_keyfile = privkey.pem
40distinguished_name = req_distinguished_name
41attributes = req_attributes
42x509_extensions = v3_ca
43string_mask = nombstr
44
45[ req_distinguished_name ]
46countryName = Country Name (2 letter code)
e3a8510a
MT
47countryName_default = DE
48countryName_min = 2
49countryName_max = 2
cd1a2927
MT
50
51stateOrProvinceName = State or Province Name (full name)
52stateOrProvinceName_default =
53
54localityName = Locality Name (eg, city)
55#localityName_default =
56
570.organizationName = Organization Name (eg, company)
e3a8510a 580.organizationName_default = IPFire
cd1a2927
MT
59
60organizationalUnitName = Organizational Unit Name (eg, section)
61#organizationalUnitName_default =
62
63commonName = Common Name (eg, your name or your server\'s hostname)
e3a8510a 64commonName_max = 64
cd1a2927
MT
65
66emailAddress = Email Address
67emailAddress_max = 40
68
69[ req_attributes ]
70challengePassword = A challenge password
e3a8510a
MT
71challengePassword_min = 4
72challengePassword_max = 20
cd1a2927
MT
73unstructuredName = An optional company name
74
75[ usr_cert ]
76basicConstraints=CA:FALSE
77nsComment = "OpenSSL Generated Certificate"
78subjectKeyIdentifier=hash
79authorityKeyIdentifier=keyid,issuer:always
80
81[ v3_req ]
82basicConstraints = CA:FALSE
83keyUsage = nonRepudiation, digitalSignature, keyEncipherment
84
85[ v3_ca ]
86subjectKeyIdentifier=hash
87authorityKeyIdentifier=keyid:always,issuer:always
88basicConstraints = CA:true
89
90[ crl_ext ]
91authorityKeyIdentifier=keyid:always,issuer:always
92
93[ engine ]
94default = openssl