diff options
author | Erich Eckner <git@eckner.net> | 2019-09-02 11:47:33 +0200 |
---|---|---|
committer | Erich Eckner <git@eckner.net> | 2019-09-02 12:03:10 +0200 |
commit | ff7a3622bc6b8002a2ca6c8c26668f4e1daa70df (patch) | |
tree | ab4993267e075f24c0d3717bb05b28772fbb1728 /etc/server-ssl.conf | |
parent | 4b146b607885a0a0543c68ee553f7a6c64e1fe30 (diff) | |
download | simple-pki-ff7a3622bc6b8002a2ca6c8c26668f4e1daa70df.tar.xz |
sign-ca functional
Diffstat (limited to 'etc/server-ssl.conf')
-rw-r--r-- | etc/server-ssl.conf | 30 |
1 files changed, 30 insertions, 0 deletions
diff --git a/etc/server-ssl.conf b/etc/server-ssl.conf new file mode 100644 index 0000000..337a7a4 --- /dev/null +++ b/etc/server-ssl.conf @@ -0,0 +1,30 @@ +# TLS server certificate request + +# This file is used by the openssl req command. The subjectAltName cannot be +# prompted for and must be specified in the SAN environment variable. + +[ default ] +SAN = $ENV::SAN # Default value + +[ req ] +default_bits = 2048 # RSA key size +encrypt_key = no # Protect private key +default_md = sha1 # MD to use +utf8 = yes # Input is UTF-8 +string_mask = utf8only # Emit UTF-8 strings +prompt = no # Prompt for DN +distinguished_name = server_dn # DN template +req_extensions = server_reqext # Desired extensions + +[ server_dn ] +0.domainComponent = "net" +1.domainComponent = "eckner" +organizationName = "Eckner Net" +organizationalUnitName = "Eckner Net Https" +commonName = $ENV::CN + +[ server_reqext ] +keyUsage = critical,digitalSignature,keyEncipherment +extendedKeyUsage = serverAuth,clientAuth +subjectKeyIdentifier = hash +subjectAltName = $ENV::SAN |