# $Id: globus-host-ssl.conf.1c3f2ca8,v 1.1 2003/05/22 22:38:22 helm Exp $ # Transformed into doesgrids-host-ssl.conf by Randy Reitz, Fermilab 3/23/2004 # # # SSLeay example configuration file. # This is mostly being used for generation of certificate requests. # # TAR: Changed this line to prevent Windows from kack'ing #RANDFILE = $ENV::HOME/.rnd RANDFILE = ./.rnd #################################################################### [ ca ] default_ca = CA_default # The default ca section #################################################################### [ CA_default ] dir = ./demoCA # Where everything is kept certs = $dir/certs # Where the issued certs are kept crl_dir = $dir/crl # Where the issued crl are kept database = $dir/index.txt # database index file. new_certs_dir = $dir/newcerts # default place for new certs. certificate = $dir/cacert.pem # The CA certificate serial = $dir/serial # The current serial number crl = $dir/crl.pem # The current CRL private_key = $dir/private/cakey.pem# The private key RANDFILE = $dir/private/.rand # private random number file x509_extensions = x509v3_extensions # The extentions to add to the cert default_days = 365 # how long to certify for default_crl_days= 365 # DEE 30 # how long before next CRL default_md = md5 # which md to use. preserve = no # keep passed DN ordering # A few difference way of specifying how similar the request should look # For type CA, the listed attributes must be the same, and the optional # and supplied fields are just that :-) policy = policy_match # For the CA policy [ policy_match ] countryName = match stateOrProvinceName = optional organizationName = match organizationalUnitName = optional commonName = supplied emailAddress = optional # For the 'anything' policy # At this point in time, you must list all acceptable 'object' # types. [ policy_anything ] countryName = optional stateOrProvinceName = optional localityName = optional organizationName = optional organizationalUnitName = optional commonName = supplied emailAddress = optional #################################################################### [ req ] default_bits = 1024 default_keyfile = privkey.pem distinguished_name = req_distinguished_name attributes = req_attributes [ req_distinguished_name ] # BEGIN CONFIG 0.domainComponent = Level 0 DomainComponent 0.domainComponent_default = org 1.domainComponent = Level 1 DomainComponent 1.domainComponent_default = doegrids #organizationName = Organization #organizationName_default = Fermilab organizationalUnitName = Certificate category organizationalUnitName_default = Services 0.commonName = Regex Expression, e.g., (a|b|c...).bar.com 0.commonName_max = 64 #1.commonName = Name 1, e.g., a.bar.com #1.commonName_max = 64 #2.commonName = Name 2, e.g., b.bar.com #2.commonName_max = 64 #3.commonName = Name 3, e.g., c.bar.com #3.commonName_max = 64 # END CONFIG [ req_attributes ] #challengePassword = A challenge password #challengePassword_min = 6 #challengePassword_max = 20 #unstructuredName = An optional company name [ x509v3_extensions ] #nsCaRevocationUrl = http://www.globus.org/ca-crl.pem #nsComment = "This is a comment" # under ASN.1, the 0 bit would be encoded as 80 nsCertType = 0x40 #nsBaseUrl #nsRevocationUrl #nsRenewalUrl #nsCaPolicyUrl #nsSslServerName #nsCertSequence #nsCertExt #nsDataType # $Log: globus-host-ssl.conf.1c3f2ca8,v $ # Revision 1.1 2003/05/22 22:38:22 helm # *** empty log message *** # # Revision 1.1 2003/05/13 20:05:35 helm # move support files to hash name # # Revision 1.4 2003/05/09 22:15:10 helm # lower case # # Revision 1.3 2003/05/03 01:34:17 dhiva # This config file was prepared by Mary Thompson # Changes: # Replaced the OIDs with DomainComponent # # Revision 1.2 2003/05/03 01:18:09 dhiva # $Id: globus-host-ssl.conf.1c3f2ca8,v 1.1 2003/05/22 22:38:22 helm Exp $ included for all these files # # Revision 1.1 2003/05/03 01:15:06 dhiva # Globus Support Files for pki1.doegrids.org CA #