pkiutilities/ocsp/test/server/OpenSSL/openssl.config
author Dremov Kirill (Nokia-D-MSW/Tampere) <kirill.dremov@nokia.com>
Tue, 26 Jan 2010 15:20:08 +0200
changeset 0 164170e6151a
permissions -rw-r--r--
Revision: 201004

# openssl.config
#
# Config file for OpenSSL CA

[ ca ]

default_ca      = ca_default            # The default ca section

[ ca1 ]

dir            = ./ca1
database       = $dir/index.txt         # index file.
new_certs_dir  = $dir/certs             # new certs dir

certificate    = $dir/cacert.pem        # The CA cert
serial         = $dir/serial            # serial no file
private_key    = $dir/private/cakey.pem # CA private key
RANDFILE       = $dir/private/.rand     # random number file

default_days   = 365                    # how long to certify for
default_crl_days= 30                    # how long before next CRL
default_md     = md5                    # md to use

policy         = ca_policy              # our policy
email_in_dn    = no                     # Don't add the email into cert DN

nameopt        = default_ca             # Subject name display option
certopt        = default_ca             # Certificate display option
copy_extensions = none                  # Don't copy extensions from request

[ ca2 ]

dir            = ./ca2
database       = $dir/index.txt         # index file.
new_certs_dir  = $dir/certs             # new certs dir

certificate    = $dir/cacert.pem        # The CA cert
serial         = $dir/serial            # serial no file
private_key    = $dir/private/cakey.pem # CA private key
RANDFILE       = $dir/private/.rand     # random number file

default_days   = 365                    # how long to certify for
default_crl_days= 30                    # how long before next CRL
default_md     = md5                    # md to use

policy         = ca_policy              # our policy
email_in_dn    = no                     # Don't add the email into cert DN

nameopt        = default_ca             # Subject name display option
certopt        = default_ca             # Certificate display option
copy_extensions = none                  # Don't copy extensions from request

[ ca_policy ]

organizationName       = supplied
commonName             = supplied