# # YACHT (Yet Another CA How To) Placed in public domain. RLamb 2019 # HOME = . RANDFILE = $ENV::HOME/rnd oid_section = new_oids [ new_oids ] businessCategory = 2.5.4.15 jurisdictionC = 1.3.6.1.4.1.311.60.2.1.3 ipsecEndSystem = 1.3.6.1.5.5.7.3.5 ipsecTunnel = 1.3.6.1.5.5.7.3.6 ipsecUser = 1.3.6.1.5.5.7.3.7 ocsp = 1.3.6.1.5.5.7.3.9 ocspnorevcheck = 1.3.6.1.5.5.7.48.1.5 [ ca ] default_ca = req [ req ] serial = serial database = index.txt new_certs_dir = newcerts crlnumber = crlnumber default_crl_days = 7 default_md = sha256 default_days = 365 prompt = no x509_extensions = v3_ca policy = my_policy [ my_policy ] CN = supplied OU = supplied O = supplied street = supplied L = supplied ST = supplied postalCode = supplied C = supplied businessCategory = supplied jurisdictionST = supplied jurisdictionC = supplied serialNumber = supplied [ v3_ca ] subjectKeyIdentifier=hash authorityKeyIdentifier=keyid:always,issuer # export SAN=`openssl req -in www/new.csr -noout -text | grep -A1 "X509v3 Subject Alternative Name:" | tail -1` subjectAltName=${ENV::SAN} # or @alt_names basicConstraints = CA:false extendedKeyUsage=serverAuth,clientAuth keyUsage = digitalSignature, keyEncipherment # DV=2.23.140.1.2.1 EV=2.23.140.1.1 OV=2.23.140.1.2.2 # EV-code=2.23.140.1.3 test=2.23.140.2.1 from https://cabforum.org/object-registry/ # Use DV policy certificatePolicies=ia5org,2.23.140.1.2.1,@polsect # CRL overhead too high? # crlDistributionPoints=URI:http://www.example.com/ca/www/ca.crl authorityInfoAccess = caIssuers;URI:http://www.example.com/ca/www/ca.cer,OCSP;URI:http://www.example.com/ca/www/ocsp/ [polsect] policyIdentifier = 1.3.6.1.4.1.35617.1.2.1.1.1 # XtcN PEN CPS.1="https://www.example.com/ca/www/cps/" #userNotice.1=@notice [notice] explicitText="Explicit Text Here" organization="example incorporated" noticeNumbers=1,2,3 [alt_names] DNS.1 = your-website.dev DNS.2 = another-website.dev [ ocsp ] serial = serial database = index.txt new_certs_dir = newcerts crlnumber = crlnumber default_crl_days = 7 default_md = sha256 default_days = 365 prompt = no x509_extensions = ocsp_ext policy = ocsp_policy [ ocsp_policy ] CN = supplied [ ocsp_ext ] subjectKeyIdentifier=hash authorityKeyIdentifier=keyid:always,issuer basicConstraints = CA:false extendedKeyUsage=ocsp keyUsage = digitalSignature, keyEncipherment certificatePolicies=ia5org,ocsp,@ocsp_polsect ocspnorevcheck=ASN1:NULL authorityInfoAccess = caIssuers;URI:http://www.example.com/ca/www/ca.cer,OCSP;URI:http://www.example.com/ca/www/ocsp/ [ocsp_polsect] policyIdentifier = 1.3.6.1.4.1.35617.1.2.1.1.1 # XtcN PEN CPS.1="https://www.example.com/ca/www/cps/"