# # Copyright (c) ZeroC, Inc. All rights reserved. # # # ZeroC base OpenSSL configuration file. # ############################################################################### ### Self Signed Root Certificate ############################################################################### [ ca ] default_ca = ice [ ice ] default_days = 365 # How long certs are valid. default_md = md5 # The Message Digest type. preserve = no # Keep passed DN ordering? [ req ] default_bits = 2048 default_keyfile = $ENV::ICE_HOME/certs/ca/cakey.pem default_md = md5 prompt = no distinguished_name = root_ca_distinguished_name x509_extensions = root_ca_extensions [ root_ca_distinguished_name ] countryName = US stateOrProvinceName = Some State localityName = Somewhere organizationName = Your Company organizationalUnitName = Development commonName = Your Certificate Authority emailAddress = you@some.net [ root_ca_extensions ] basicConstraints = CA:true # PKIX recommendation. subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer:always