Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 2 additions & 3 deletions easyrsa3/openssl-easyrsa.cnf
Original file line number Diff line number Diff line change
Expand Up @@ -113,15 +113,14 @@ serialNumber_default = $ENV::EASYRSA_REQ_SERIAL
[ basic_exts ]
basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always

# The Easy-RSA CA extensions
[ easyrsa_ca ]

# PKIX recommendations:

subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid:always,issuer:always

# This could be marked critical, but it's nice to support reading by any
# broken clients who attempt to do so.
Expand All @@ -143,4 +142,4 @@ keyUsage = cRLSign, keyCertSign
# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL.

# issuerAltName=issuer:copy
authorityKeyIdentifier=keyid:always,issuer:always
authorityKeyIdentifier=keyid:always
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/ca
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@

basicConstraints = CA:TRUE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer:always
authorityKeyIdentifier = keyid:always
keyUsage = cRLSign, keyCertSign
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/client
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = clientAuth
keyUsage = digitalSignature
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/code-signing
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = codeSigning
keyUsage = digitalSignature
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/email
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = emailProtection
keyUsage = digitalSignature,keyEncipherment,nonRepudiation
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/kdc
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = 1.3.6.1.5.2.3.5
keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement
issuerAltName = issuer:copy
Expand Down
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/server
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = serverAuth
keyUsage = digitalSignature,keyEncipherment
2 changes: 1 addition & 1 deletion easyrsa3/x509-types/serverClient
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

basicConstraints = CA:FALSE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer:always
authorityKeyIdentifier = keyid:always
extendedKeyUsage = serverAuth,clientAuth
keyUsage = digitalSignature,keyEncipherment