13 new_certs_dir=newcerts
20 x509_extensions = v3_ca
26 basicConstraints = critical, CA:FALSE
27 keyUsage = critical, digitalSignature, keyEncipherment, keyAgreement
28 extendedKeyUsage = clientAuth, serverAuth, nsSGC, msSGC
33 subjectAltName = optional
34 organizationName = optional
35 organizationalUnitName = optional
36 emailAddress = optional
37 countryName = optional
38 stateOrProvinceName = optional
39 localityName = optional