# SAN Extension # Copy, then add DNS.1 = name, etc # [ server_cert ] # Extensions for server certificates (`man x509v3_config`). basicConstraints = CA:FALSE nsCertType = server, client nsComment = "OpenSSL Generated Server Certificate" subjectKeyIdentifier = hash authorityKeyIdentifier = keyid,issuer:always keyUsage = critical, digitalSignature, keyEncipherment, nonRepudiation extendedKeyUsage = serverAuth, clientAuth subjectAltName = @alt_names [ alt_names ]