blob: 37207e8bd01970662893c765a4207301cb7aaf0e [file] [log] [blame]
Chetan Gaonker7f4bf742016-05-04 15:56:08 -07001[ ca ]
2default_ca = CA_default
3
4[ CA_default ]
5dir = ./
6certs = $dir
7crl_dir = $dir/crl
8database = $dir/index.txt
9new_certs_dir = $dir
10certificate = $dir/ca.pem
11serial = $dir/serial
12crl = $dir/crl.pem
13private_key = $dir/ca.key
14RANDFILE = $dir/.rand
15name_opt = ca_default
16cert_opt = ca_default
17default_days = 360
18default_crl_days = 300
19default_md = sha1
20preserve = no
21policy = policy_match
22crlDistributionPoints = URI:http://www.example.com/example_ca.crl
23
24[ policy_match ]
25countryName = match
26stateOrProvinceName = match
27organizationName = match
28organizationalUnitName = optional
29commonName = supplied
30emailAddress = optional
31
32[ policy_anything ]
33countryName = optional
34stateOrProvinceName = optional
35localityName = optional
36organizationName = optional
37organizationalUnitName = optional
38commonName = supplied
39emailAddress = optional
40
41[ req ]
42prompt = no
43distinguished_name = certificate_authority
44default_bits = 2048
45input_password = whatever
46output_password = whatever
47x509_extensions = v3_ca
48
49[certificate_authority]
50countryName = US
51stateOrProvinceName = CA
52localityName = Somewhere
53organizationName = Ciena Inc.
54emailAddress = admin@ciena.com
55commonName = "Example Certificate Authority"
56
57[v3_ca]
58subjectKeyIdentifier = hash
59authorityKeyIdentifier = keyid:always,issuer:always
60basicConstraints = CA:true
61crlDistributionPoints = URI:http://www.example.com/example_ca.crl
62