OpenSSL configuration file parameters

Last Updated : Mar 19, 2021 |

The following table lists the OpenSSL configuration file parameters that you need to update:

Text to update

Required changes

[ CA_default ] section

dir            = ../../CA
dir            = ./CA
nsComment                      = "OpenSSL Generated Certificate"
#nsComment                    = "OpenSSL Generated Certificate"
# X.509v3 extensions to use:
# extensions           =
# X.509v3 extensions to use:
extensions           = v3_req
# req_extensions = v3_req # The extensions to add to a certificate request.
req_extensions = v3_req # The extensions to add to a certificate request.

[ v3_req ] section

keyUsage = nonRepudiation, digitalSignature, keyEncipherment
keyUsage = nonRepudiation, digitalSignature, keyEncipherment, dataEncipherment
extendedKeyUsage=serverAuth,clientAuth

[ usr_cert ] section

# These extensions are added when 'ca' signs a request.
# These extensions are added when 'ca' signs a request.
keyUsage = nonRepudiation, digitalSignature, keyEncipherment, dataEncipherment
extendedKeyUsage=serverAuth,clientAuth

[ req ] section

string_mask
string_mask = MASK:0x2002
default_md = sha1
default_md = sha256