Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 8 additions & 7 deletions perl/openssl.conf
Original file line number Diff line number Diff line change
Expand Up @@ -75,14 +75,15 @@ keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
crlDistributionPoints = $ENV::KEY_CRL_LOC

# Client certificate extensions
# Client certificate request extensions.
# Note: authorityKeyIdentifier is omitted — this section is used as
# req_extensions (CSR creation) where the issuer is not yet known.
# LibreSSL correctly rejects AKI in that context.
[ v3_req ]
basicConstraints = critical, CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid, issuer
keyUsage = critical, nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth
crlDistributionPoints = $ENV::KEY_CRL_LOC
basicConstraints = critical, CA:FALSE
keyUsage = critical, nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth
crlDistributionPoints = $ENV::KEY_CRL_LOC

# CA certificate extensions
# pathlen:0 limits the CA to signing end-entity certs only.
Expand Down
Loading