test-ca.opensslconf 2.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. [req]
  2. x509_extensions = v3_ca
  3. distinguished_name = req_dn
  4. [req_dn]
  5. countryName = NL
  6. organizationalUnitName = PolarSSL
  7. commonName = PolarSSL Test CA
  8. [v3_ca]
  9. subjectKeyIdentifier=hash
  10. authorityKeyIdentifier=keyid:always,issuer:always
  11. basicConstraints = CA:true
  12. [othername_san]
  13. subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:hw_module_name
  14. [nonprintable_othername_san]
  15. subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:nonprintable_hw_module_name
  16. [unsupported_othername_san]
  17. subjectAltName=otherName:1.2.3.4;UTF8:some other identifier
  18. [dns_alt_names]
  19. subjectAltName=DNS:example.com, DNS:example.net, DNS:*.example.org
  20. [rfc822name_names]
  21. subjectAltName=email:my@other.address,email:second@other.address
  22. [alt_names]
  23. DNS.1=example.com
  24. otherName.1=1.3.6.1.5.5.7.8.4;SEQ:hw_module_name
  25. DNS.2=example.net
  26. DNS.3=*.example.org
  27. [multiple_san]
  28. subjectAltName=@alt_names
  29. [hw_module_name]
  30. hwtype = OID:1.3.6.1.4.1.17.3
  31. hwserial = OCT:123456
  32. [nonprintable_hw_module_name]
  33. hwtype = OID:1.3.6.1.4.1.17.3
  34. hwserial = FORMAT:HEX, OCT:3132338081008180333231
  35. [v3_any_policy_ca]
  36. basicConstraints = CA:true
  37. certificatePolicies = 2.5.29.32.0
  38. [v3_any_policy_qualifier_ca]
  39. basicConstraints = CA:true
  40. certificatePolicies = @policy_info
  41. [v3_multi_policy_ca]
  42. basicConstraints = CA:true
  43. certificatePolicies = 1.2.3.4,2.5.29.32.0
  44. [v3_unsupported_policy_ca]
  45. basicConstraints = CA:true
  46. certificatePolicies = 1.2.3.4
  47. [policy_info]
  48. policyIdentifier = 2.5.29.32.0
  49. CPS.1 ="CPS uri string"
  50. [fan_cert]
  51. extendedKeyUsage = 1.3.6.1.4.1.45605.1
  52. [noext_ca]
  53. basicConstraints = CA:true
  54. [test_ca]
  55. database = /dev/null
  56. [crl_ext_idp]
  57. issuingDistributionPoint=critical, @idpdata
  58. [crl_ext_idp_nc]
  59. issuingDistributionPoint=@idpdata
  60. [idpdata]
  61. fullname=URI:http://pki.example.com/
  62. # these IPs are the ascii values for 'abcd' and 'abcd.example.com'
  63. [tricky_ip_san]
  64. subjectAltName=IP:97.98.99.100,IP:6162:6364:2e65:7861:6d70:6c65:2e63:6f6d
  65. [csr_ext_v3_keyUsage]
  66. keyUsage = digitalSignature, keyEncipherment
  67. [csr_ext_v3_subjectAltName]
  68. subjectAltName=DNS:example.com, DNS:example.net, DNS:*.example.org
  69. [csr_ext_v3_nsCertType]
  70. nsCertType=server
  71. [csr_ext_v3_all]
  72. keyUsage = cRLSign
  73. subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:nonprintable_hw_module_name
  74. nsCertType=client