Created
January 18, 2025 10:43
-
-
Save subudear/9b110099fe10bd99a15316faf22bef1a to your computer and use it in GitHub Desktop.
CA root_certificate
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# This is used with the 'openssl ca' command to sign a request | |
[ca] | |
default_ca = CA | |
[CA] | |
# Where OpenSSL stores information | |
dir = . | |
certs = $dir/certs | |
crldir = $dir/crldir | |
new_certs_dir = $certs/newcerts | |
database = $dir/index | |
certificate = $certs/rootcrt.pem | |
private_key = $dir/rootprivkey.pem | |
crl = $crldir/crl.pem | |
serial = $dir/serial.txt | |
RANDFILE = $dir/.rand | |
# How OpenSSL will display certificate after signing | |
name_opt = ca_default | |
cert_opt = ca_default | |
# How long the CA certificate is valid for | |
default_days = 3650 | |
# The message digest for self-signing the certificate | |
default_md = sha512 | |
# Subjects don't have to be unique in this CA's database | |
unique_subject = no | |
# What to do with CSR extensions | |
copy_extensions = copy | |
# Rules on mandatory or optional DN components | |
policy = simple_policy | |
# Extensions added while singing with the `openssl ca` command | |
x509_extensions = x509_ext | |
[simple_policy] | |
countryName = optional | |
stateOrProvinceName = optional | |
localityName = optional | |
organizationName = optional | |
organizationalUnitName = optional | |
commonName = optional | |
domainComponent = optional | |
emailAddress = optional | |
name = optional | |
surname = optional | |
givenName = optional | |
dnQualifier = optional | |
[ x509_ext ] | |
# These extensions are for a CA certificate | |
subjectKeyIdentifier = hash | |
authorityKeyIdentifier = keyid:always | |
basicConstraints = critical, CA:TRUE | |
keyUsage = critical, keyCertSign, cRLSign, digitalSignature |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment