1
extensions = extension_section
2
x509_extensions = extension_section
6
distinguished_name = req_dn
11
#1.domainComponent = DNS domain Component
12
#1.domainComponent_default = "com"
13
#2.domainComponent = DNS domain Component
14
#2.domainComponent_default = "localhost"
16
countryName = ISO country code
17
countryName_default = "XX"
19
stateOrProvinceName = State/Province Name
20
stateOrProvinceName_default = ""
22
localityName = Location
23
localityName_default = ""
25
organizationName = Organization
26
organizationName_default = "Looser Org."
28
organizationalUnitName = Organizational Unit Name
29
organizationalUnitName_default = "bad CA!"
31
commonName = Common Name
32
commonName_default = "AuthCerts TestCA"
38
basicConstraints=critical,CA:true
39
subjectKeyIdentifier=hash
40
authorityKeyIdentifier=keyid:always,issuer:always
41
keyUsage = cRLSign, keyCertSign
42
subjectAltName = URI:"http://localhost/pyca/get-cert.py/AuthCerts/ca.crt"
43
issuerAltName = issuer:copy
44
crlDistributionPoints = URI:"http://localhost/pyca/get-cert.py/Root/crl.crl"
45
#certificatePolicies=ia5org,@polsect
47
# Netscape cert extensions
48
nsComment = "This CA issues SSL client certificates."
49
nsCaPolicyUrl = "https://localhost/AuthCerts/policy.html"
51
nsCaRevocationUrl = "http://localhost/pyca/get-cert.py/Root/crl.crl"
54
#policyIdentifier=1.2.3.4
55
#CPS="https://localhost/AuthCerts/policy.html"
59
explicitText="This CA issues SSL client certificates."
60
organization="Looser Org. with bad CA admin."