2 # Copy, then add DNS.1 = name, etc
5 # Extensions for server certificates (`man x509v3_config`).
6 basicConstraints = CA:FALSE
7 nsCertType = server, client
8 nsComment = "OpenSSL Generated Server Certificate"
9 subjectKeyIdentifier = hash
10 authorityKeyIdentifier = keyid,issuer:always
11 keyUsage = critical, digitalSignature, keyEncipherment, nonRepudiation
12 extendedKeyUsage = serverAuth, clientAuth
13 subjectAltName = @alt_names