Correction : X.509 Key Usage.
[lhc/ateliers.git] / etc / openssl / demo.burette.heureux-cyclage.org / host.cfg
index 1745059..748b191 100644 (file)
@@ -1,4 +1,4 @@
-       SERVICE     = demo_burette
+       SERVICE     = demo.burette
        RANDFILE    = var/sec/x509/openssl.rand
        oid_section = extra_oids
 [ extra_oids ]
@@ -25,9 +25,9 @@
        jurisdictionOfIncorporationStateOrProvinceName = $ENV::x509_state_or_province
        jurisdictionOfIncorporationCountryName         = $ENV::x509_country
 [ extensions ]
-       basicConstraints       = critical,CA:TRUE,pathlen:0
-       keyUsage               = keyCertSign,cRLSign,digitalSignature,keyEncipherment
-       subjectAltName         = email:contact+$SERVICE@$ENV::x509_host,DNS:burette.heureux-cyclage.org
+       basicConstraints       = critical,CA:FALSE,pathlen:0
+       keyUsage               = keyEncipherment
+       subjectAltName         = email:contact+$SERVICE@$ENV::x509_host,DNS:demo.burette.heureux-cyclage.org
        subjectKeyIdentifier   = hash
        issuerAltName          = issuer:copy
        authorityKeyIdentifier = keyid:always,issuer:always
@@ -37,7 +37,7 @@
 [ self_signed_extensions ]
        basicConstraints       = critical,CA:TRUE,pathlen:0
        keyUsage               = keyCertSign,cRLSign,digitalSignature,keyEncipherment
-       subjectAltName         = email:contact+$SERVICE@$ENV::x509_host,DNS:burette.heureux-cyclage.org
+       subjectAltName         = email:contact+$SERVICE@$ENV::x509_host,DNS:demo.burette.heureux-cyclage.org
        subjectKeyIdentifier   = hash
        issuerAltName          = issuer:copy
        authorityKeyIdentifier = keyid:always,issuer:always