]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - config/ssl/openssl.cnf
del_rand: Deletion of RAND file in openssl config
[people/pmueller/ipfire-2.x.git] / config / ssl / openssl.cnf
CommitLineData
cd1a2927 1HOME = .
cd1a2927
MT
2oid_section = new_oids
3
4[ new_oids ]
5
6[ ca ]
33a31f1a 7default_ca = IPFire
cd1a2927 8
1ce6d696 9[ IPFire ]
33a31f1a 10dir = /var/ipfire
cd1a2927 11certs = $dir/certs
e3a8510a 12crl_dir = $dir/crls
cd1a2927
MT
13database = $dir/certs/index.txt
14new_certs_dir = $dir/certs
15certificate = $dir/ca/cacert.pem
16serial = $dir/certs/serial
17crl = $dir/crls/cacrl.pem
18private_key = $dir/private/cakey.pem
cd1a2927
MT
19x509_extensions = usr_cert
20default_days = 999999
21default_crl_days= 30
3847730c 22default_md = sha256
cd1a2927
MT
23preserve = no
24policy = policy_match
25email_in_dn = no
26
27[ policy_match ]
28countryName = optional
29stateOrProvinceName = optional
30organizationName = optional
31organizationalUnitName = optional
32commonName = supplied
33emailAddress = optional
34
35[ req ]
3847730c 36default_bits = 2048
cd1a2927
MT
37default_keyfile = privkey.pem
38distinguished_name = req_distinguished_name
39attributes = req_attributes
40x509_extensions = v3_ca
41string_mask = nombstr
42
43[ req_distinguished_name ]
44countryName = Country Name (2 letter code)
e3a8510a
MT
45countryName_default = DE
46countryName_min = 2
47countryName_max = 2
cd1a2927
MT
48
49stateOrProvinceName = State or Province Name (full name)
50stateOrProvinceName_default =
51
52localityName = Locality Name (eg, city)
53#localityName_default =
54
550.organizationName = Organization Name (eg, company)
e3a8510a 560.organizationName_default = IPFire
cd1a2927
MT
57
58organizationalUnitName = Organizational Unit Name (eg, section)
59#organizationalUnitName_default =
60
61commonName = Common Name (eg, your name or your server\'s hostname)
e3a8510a 62commonName_max = 64
cd1a2927
MT
63
64emailAddress = Email Address
65emailAddress_max = 40
66
67[ req_attributes ]
68challengePassword = A challenge password
e3a8510a
MT
69challengePassword_min = 4
70challengePassword_max = 20
cd1a2927
MT
71unstructuredName = An optional company name
72
73[ usr_cert ]
74basicConstraints=CA:FALSE
75nsComment = "OpenSSL Generated Certificate"
76subjectKeyIdentifier=hash
77authorityKeyIdentifier=keyid,issuer:always
78
79[ v3_req ]
80basicConstraints = CA:FALSE
81keyUsage = nonRepudiation, digitalSignature, keyEncipherment
82
83[ v3_ca ]
84subjectKeyIdentifier=hash
85authorityKeyIdentifier=keyid:always,issuer:always
86basicConstraints = CA:true
87
88[ crl_ext ]
89authorityKeyIdentifier=keyid:always,issuer:always
90
91[ engine ]
92default = openssl