Index: net/data/ssl/scripts/policy.cnf |
diff --git a/net/data/ssl/scripts/aia-test.cnf b/net/data/ssl/scripts/policy.cnf |
similarity index 76% |
copy from net/data/ssl/scripts/aia-test.cnf |
copy to net/data/ssl/scripts/policy.cnf |
index f89d68a8842ab778de325c2c1b2cb24071fac896..80558bfc7b648baa19d074551f03a098643745da 100644 |
--- a/net/data/ssl/scripts/aia-test.cnf |
+++ b/net/data/ssl/scripts/policy.cnf |
@@ -1,6 +1,5 @@ |
CA_DIR=out |
-CA_NAME=aia-test-root |
-AIA_URL=http://aia-test.invalid |
+CA_NAME=policy-root |
[ca] |
default_ca = CA_root |
@@ -26,11 +25,17 @@ copy_extensions = copy |
[user_cert] |
basicConstraints = critical, CA:false |
extendedKeyUsage = serverAuth, clientAuth |
-authorityInfoAccess = caIssuers;URI:${ENV::AIA_URL} |
+certificatePolicies = 1.2.3.4 |
[ca_cert] |
basicConstraints = critical, CA:true |
-keyUsage = critical, keyCertSign, cRLSign |
+keyUsage = critical, digitalSignature, keyCertSign, cRLSign |
+ |
+[intermediate_cert] |
+basicConstraints = critical, CA:true |
+keyUsage = critical, digitalSignature, keyCertSign, cRLSign |
+policyConstraints = requireExplicitPolicy:0 |
+certificatePolicies = 1.2.3.4, 1.2.3.4.5, 1.2.3.5 |
[policy_anything] |
# Default signing policy |