Blame | Last modification | View Log | RSS feed
# X509 extensions for a KDC server certificatebasicConstraints = CA:FALSEsubjectKeyIdentifier = hashauthorityKeyIdentifier = keyid,issuer:alwaysextendedKeyUsage = 1.3.6.1.5.2.3.5keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreementissuerAltName = issuer:copysubjectAltName = otherName:1.3.6.1.5.2.2;SEQUENCE:kdc_princ_name[kdc_princ_name]realm = EXP:0,GeneralString:${ENV::EASYRSA_KDC_REALM}principal_name = EXP:1,SEQUENCE:kdc_principal_seq[kdc_principal_seq]name_type = EXP:0,INTEGER:1name_string = EXP:1,SEQUENCE:kdc_principals[kdc_principals]princ1 = GeneralString:krbtgtprinc2 = GeneralString:${ENV::EASYRSA_KDC_REALM}