<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Openssl_howto_two%2Fetc%2Fssl%2Fopenssl.cnf</id>
	<title>Openssl howto two/etc/ssl/openssl.cnf - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Openssl_howto_two%2Fetc%2Fssl%2Fopenssl.cnf"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Openssl_howto_two/etc/ssl/openssl.cnf&amp;action=history"/>
	<updated>2026-06-29T18:40:23Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Openssl_howto_two/etc/ssl/openssl.cnf&amp;diff=5669&amp;oldid=prev</id>
		<title>Thomas am 3. November 2014 um 15:09 Uhr</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Openssl_howto_two/etc/ssl/openssl.cnf&amp;diff=5669&amp;oldid=prev"/>
		<updated>2014-11-03T15:09:01Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 3. November 2014, 15:09 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l50&quot; &gt;Zeile 50:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 50:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;default_keyfile         = privkey.pem&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;default_keyfile         = privkey.pem&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;distinguished_name      = req_distinguished_name&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;distinguished_name      = req_distinguished_name&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;      distinguished_name      = req_distinguished_name&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;attributes              = req_attributes&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;attributes              = req_attributes&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;x509_extensions = v3_ca # The extentions to add to the self signed cert&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;x509_extensions = v3_ca # The extentions to add to the self signed cert&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key my_wiki:diff::1.12:old-5668:rev-5669 --&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Openssl_howto_two/etc/ssl/openssl.cnf&amp;diff=5668&amp;oldid=prev</id>
		<title>Thomas: Die Seite wurde neu angelegt: „&lt;pre&gt; HOME                    = . RANDFILE                = $ENV::HOME/.rnd oid_section             = new_oids [ new_oids ] tsa_policy1 = 1.2.3.4.1 tsa_policy2 = …“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Openssl_howto_two/etc/ssl/openssl.cnf&amp;diff=5668&amp;oldid=prev"/>
		<updated>2014-11-03T15:08:27Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „&amp;lt;pre&amp;gt; HOME                    = . RANDFILE                = $ENV::HOME/.rnd oid_section             = new_oids [ new_oids ] tsa_policy1 = 1.2.3.4.1 tsa_policy2 = …“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
HOME                    = .&lt;br /&gt;
RANDFILE                = $ENV::HOME/.rnd&lt;br /&gt;
oid_section             = new_oids&lt;br /&gt;
[ new_oids ]&lt;br /&gt;
tsa_policy1 = 1.2.3.4.1&lt;br /&gt;
tsa_policy2 = 1.2.3.4.5.6&lt;br /&gt;
tsa_policy3 = 1.2.3.4.5.7&lt;br /&gt;
[ ca ]&lt;br /&gt;
default_ca      = CA_default            # The default ca section&lt;br /&gt;
[ CA_default ]&lt;br /&gt;
dir             = .                     # Where everything is kept&lt;br /&gt;
certs           = $dir/certs            # Where the issued certs are kept&lt;br /&gt;
crl_dir         = $dir/crl              # Where the issued crl are kept&lt;br /&gt;
database        = $dir/index.txt        # database index file.&lt;br /&gt;
                                        # several ctificates with same subject.&lt;br /&gt;
new_certs_dir   = $dir/newcerts         # default place for new certs.&lt;br /&gt;
certificate     = $dir/cacert.pem       # The CA certificate&lt;br /&gt;
serial          = $dir/serial           # The current serial number&lt;br /&gt;
crlnumber       = $dir/crlnumber        # the current crl number&lt;br /&gt;
                                        # must be commented out to leave a V1 CRL&lt;br /&gt;
crl             = $dir/crl.pem          # The current CRL&lt;br /&gt;
private_key     = $dir/private/cakey.pem# The private key&lt;br /&gt;
RANDFILE        = $dir/private/.rand    # private random number file&lt;br /&gt;
x509_extensions = usr_cert              # The extentions to add to the cert&lt;br /&gt;
name_opt        = ca_default            # Subject Name options&lt;br /&gt;
cert_opt        = ca_default            # Certificate field options&lt;br /&gt;
default_days    = 3650                  # how long to certify for&lt;br /&gt;
default_crl_days= 30                    # how long before next CRL&lt;br /&gt;
default_md      = default               # use public key default MD&lt;br /&gt;
preserve        = no                    # keep passed DN ordering&lt;br /&gt;
policy          = policy_match&lt;br /&gt;
[ policy_match ]&lt;br /&gt;
countryName             = match&lt;br /&gt;
stateOrProvinceName     = match&lt;br /&gt;
organizationName        = match&lt;br /&gt;
organizationalUnitName  = optional&lt;br /&gt;
commonName              = supplied&lt;br /&gt;
emailAddress            = optional&lt;br /&gt;
[ policy_anything ]&lt;br /&gt;
countryName             = optional&lt;br /&gt;
stateOrProvinceName     = optional&lt;br /&gt;
localityName            = optional&lt;br /&gt;
organizationName        = optional&lt;br /&gt;
organizationalUnitName  = optional&lt;br /&gt;
commonName              = supplied&lt;br /&gt;
emailAddress            = optional&lt;br /&gt;
[ req ]&lt;br /&gt;
default_bits            = 2048&lt;br /&gt;
default_keyfile         = privkey.pem&lt;br /&gt;
distinguished_name      = req_distinguished_name&lt;br /&gt;
      distinguished_name      = req_distinguished_name&lt;br /&gt;
attributes              = req_attributes&lt;br /&gt;
x509_extensions = v3_ca # The extentions to add to the self signed cert&lt;br /&gt;
string_mask = utf8only&lt;br /&gt;
[ req_distinguished_name ]&lt;br /&gt;
countryName                     = Country Name (2 letter code)&lt;br /&gt;
countryName_default             = de&lt;br /&gt;
countryName_min                 = 2&lt;br /&gt;
countryName_max                 = 2&lt;br /&gt;
stateOrProvinceName             = State or Province Name (full name)&lt;br /&gt;
stateOrProvinceName_default     = rlp&lt;br /&gt;
localityName                    = Locality Name (eg, city)&lt;br /&gt;
localityName_default            = zw&lt;br /&gt;
0.organizationName              = Organization Name (eg, company)&lt;br /&gt;
0.organizationName_default      = xinux&lt;br /&gt;
organizationalUnitName          = Organizational Unit Name (eg, section)&lt;br /&gt;
organizationalUnitName_default  = it&lt;br /&gt;
commonName                      = Common Name (e.g. server FQDN or YOUR name)&lt;br /&gt;
commonName_max                  = 64&lt;br /&gt;
[ req_attributes ]&lt;br /&gt;
[ usr_cert ]&lt;br /&gt;
basicConstraints=CA:FALSE&lt;br /&gt;
nsComment                       = &amp;quot;OpenSSL Generated Certificate&amp;quot;&lt;br /&gt;
subjectKeyIdentifier=hash&lt;br /&gt;
authorityKeyIdentifier=keyid,issuer&lt;br /&gt;
[ v3_req ]&lt;br /&gt;
basicConstraints = CA:FALSE&lt;br /&gt;
keyUsage = nonRepudiation, digitalSignature, keyEncipherment&lt;br /&gt;
[ v3_ca ]&lt;br /&gt;
subjectKeyIdentifier=hash&lt;br /&gt;
authorityKeyIdentifier=keyid:always,issuer&lt;br /&gt;
basicConstraints = CA:true&lt;br /&gt;
[ crl_ext ]&lt;br /&gt;
authorityKeyIdentifier=keyid:always&lt;br /&gt;
[ proxy_cert_ext ]&lt;br /&gt;
basicConstraints=CA:FALSE&lt;br /&gt;
nsComment                       = &amp;quot;OpenSSL Generated Certificate&amp;quot;&lt;br /&gt;
subjectKeyIdentifier=hash&lt;br /&gt;
authorityKeyIdentifier=keyid,issuer&lt;br /&gt;
proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:3,policy:foo&lt;br /&gt;
[ tsa ]&lt;br /&gt;
default_tsa = tsa_config1       # the default TSA section&lt;br /&gt;
[ tsa_config1 ]&lt;br /&gt;
dir             = ./demoCA              # TSA root directory&lt;br /&gt;
serial          = $dir/tsaserial        # The current serial number (mandatory)&lt;br /&gt;
crypto_device   = builtin               # OpenSSL engine to use for signing&lt;br /&gt;
signer_cert     = $dir/tsacert.pem      # The TSA signing certificate&lt;br /&gt;
                                        # (optional)&lt;br /&gt;
certs           = $dir/cacert.pem       # Certificate chain to include in reply&lt;br /&gt;
                                        # (optional)&lt;br /&gt;
 signer_key      = $dir/private/tsakey.pem # The TSA private key (optional)&lt;br /&gt;
default_policy  = tsa_policy1           # Policy if request did not specify it&lt;br /&gt;
                                        # (optional)&lt;br /&gt;
other_policies  = tsa_policy2, tsa_policy3      # acceptable policies (optional)&lt;br /&gt;
digests         = md5, sha1             # Acceptable message digests (mandatory)&lt;br /&gt;
accuracy        = secs:1, millisecs:500, microsecs:100  # (optional)&lt;br /&gt;
clock_precision_digits  = 0     # number of digits after dot. (optional)&lt;br /&gt;
ordering                = yes   # Is ordering defined for timestamps?&lt;br /&gt;
                                # (optional, default: no)&lt;br /&gt;
tsa_name                = yes   # Must the TSA name be included in the reply?&lt;br /&gt;
                                # (optional, default: no)&lt;br /&gt;
ess_cert_id_chain       = no    # Must the ESS cert id chain be included?&lt;br /&gt;
                                # (optional, default: no)&lt;/div&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
</feed>