The following table lists the OpenSSL configuration file parameters that you need to update:
Text to update |
Required changes |
[ CA_default ] section |
dir = ../../CA
|
dir = ./CA
|
nsComment = "OpenSSL Generated Certificate"
|
#nsComment = "OpenSSL Generated Certificate"
|
# X.509v3 extensions to use:
# extensions =
|
# X.509v3 extensions to use:
extensions = v3_req
|
# req_extensions = v3_req # The extensions to add to a certificate request.
|
req_extensions = v3_req # The extensions to add to a certificate request.
|
[ v3_req ] section |
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
|
keyUsage = nonRepudiation, digitalSignature, keyEncipherment, dataEncipherment
extendedKeyUsage=serverAuth,clientAuth
|
[ usr_cert ] section |
# These extensions are added when 'ca' signs a request.
|
# These extensions are added when 'ca' signs a request.
keyUsage = nonRepudiation, digitalSignature, keyEncipherment, dataEncipherment
extendedKeyUsage=serverAuth,clientAuth
|
[ req ] section |
string_mask
|
string_mask = MASK:0x2002
|
|
|
|