blob: 0340e9e276352222dbb32ac6ef087aa6d04b4d47 [file] [log] [blame]
Gilles Peskinef040a172017-05-05 18:56:12 +02001[req]
2x509_extensions = v3_ca
3distinguished_name = req_dn
4
5[req_dn]
6countryName = NL
7organizationalUnitName = PolarSSL
8commonName = PolarSSL Test CA
9
10[v3_ca]
11subjectKeyIdentifier=hash
12authorityKeyIdentifier=keyid:always,issuer:always
13basicConstraints = CA:true
Manuel Pégourié-Gonnardc10afdb2017-06-29 09:48:08 +020014
Pengyu Lv0f5ca2d2023-05-25 09:24:17 +080015[no_subj_auth_id]
16subjectKeyIdentifier=none
17authorityKeyIdentifier=none
18basicConstraints = CA:true
19
Ron Eldorb2dc3fa2019-03-21 13:40:13 +020020[othername_san]
21subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:hw_module_name
22
Victor Barpp Gomesd0225af2022-09-29 11:40:20 -030023[nonprintable_othername_san]
24subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:nonprintable_hw_module_name
25
David Horstmann119d7e22022-11-25 15:50:30 +000026[unsupported_othername_san]
Ron Eldorb2dc3fa2019-03-21 13:40:13 +020027subjectAltName=otherName:1.2.3.4;UTF8:some other identifier
28
Ron Eldor9eeb8612019-02-12 15:03:42 +020029[dns_alt_names]
30subjectAltName=DNS:example.com, DNS:example.net, DNS:*.example.org
31
Przemek Stekiel608e3ef2023-02-09 14:47:50 +010032[rfc822name_names]
33subjectAltName=email:my@other.address,email:second@other.address
34
Ron Eldorb2dc3fa2019-03-21 13:40:13 +020035[alt_names]
36DNS.1=example.com
37otherName.1=1.3.6.1.5.5.7.8.4;SEQ:hw_module_name
38DNS.2=example.net
39DNS.3=*.example.org
40
41[multiple_san]
42subjectAltName=@alt_names
43
Pengyu Lve025cb22023-05-18 10:10:39 +080044[ext_multi_nocn]
45basicConstraints = CA:false
46keyUsage = digitalSignature, nonRepudiation, keyEncipherment
47subjectAltName = DNS:www.shotokan-braunschweig.de,DNS:www.massimo-abate.eu,IP:192.168.1.1,IP:192.168.69.144
48
Ron Eldorb2dc3fa2019-03-21 13:40:13 +020049[hw_module_name]
50hwtype = OID:1.3.6.1.4.1.17.3
51hwserial = OCT:123456
52
Victor Barpp Gomesd0225af2022-09-29 11:40:20 -030053[nonprintable_hw_module_name]
54hwtype = OID:1.3.6.1.4.1.17.3
55hwserial = FORMAT:HEX, OCT:3132338081008180333231
56
Ron Eldor74d9acc2019-03-21 14:00:03 +020057[v3_any_policy_ca]
58basicConstraints = CA:true
59certificatePolicies = 2.5.29.32.0
60
61[v3_any_policy_qualifier_ca]
62basicConstraints = CA:true
63certificatePolicies = @policy_info
64
65[v3_multi_policy_ca]
66basicConstraints = CA:true
67certificatePolicies = 1.2.3.4,2.5.29.32.0
68
69[v3_unsupported_policy_ca]
70basicConstraints = CA:true
71certificatePolicies = 1.2.3.4
72
73[policy_info]
74policyIdentifier = 2.5.29.32.0
75CPS.1 ="CPS uri string"
76
Ron Eldor3c4734a2019-03-25 14:05:23 +020077[fan_cert]
78extendedKeyUsage = 1.3.6.1.4.1.45605.1
79
Manuel Pégourié-Gonnardc10afdb2017-06-29 09:48:08 +020080[noext_ca]
81basicConstraints = CA:true
Gilles Peskine15ad5792018-03-22 22:21:55 +010082
Manuel Pégourié-Gonnardfd3e4fb2018-03-13 11:53:30 +010083[test_ca]
84database = /dev/null
85
86[crl_ext_idp]
87issuingDistributionPoint=critical, @idpdata
88
Manuel Pégourié-Gonnarda63305d2018-03-14 12:23:56 +010089[crl_ext_idp_nc]
90issuingDistributionPoint=@idpdata
91
Manuel Pégourié-Gonnardfd3e4fb2018-03-13 11:53:30 +010092[idpdata]
93fullname=URI:http://pki.example.com/
Manuel Pégourié-Gonnard7d2a4d82020-07-23 12:39:53 +020094
95# these IPs are the ascii values for 'abcd' and 'abcd.example.com'
96[tricky_ip_san]
97subjectAltName=IP:97.98.99.100,IP:6162:6364:2e65:7861:6d70:6c65:2e63:6f6d
Przemek Stekiele7fbbb32023-01-12 15:30:45 +010098
99[csr_ext_v3_keyUsage]
100keyUsage = digitalSignature, keyEncipherment
101
102[csr_ext_v3_subjectAltName]
103subjectAltName=DNS:example.com, DNS:example.net, DNS:*.example.org
104
105[csr_ext_v3_nsCertType]
106nsCertType=server
107
108[csr_ext_v3_all]
109keyUsage = cRLSign
110subjectAltName=otherName:1.3.6.1.5.5.7.8.4;SEQ:nonprintable_hw_module_name
111nsCertType=client
Andrzej Kureke12b01d2023-01-10 06:47:38 -0500112
113[directory_name_san]
114subjectAltName=dirName:dirname_sect
115
Andrzej Kurek7d55dd22023-06-28 04:58:19 -0400116[two_directorynames]
117subjectAltName=dirName:dirname_sect, dirName:dirname_to_malform
Andrzej Kurek4a4f1ec2023-01-12 06:51:20 -0500118
Andrzej Kureke12b01d2023-01-10 06:47:38 -0500119[dirname_sect]
120C=UK
121O=Mbed TLS
122CN=Mbed TLS directoryName SAN
Andrzej Kurek4a4f1ec2023-01-12 06:51:20 -0500123
Andrzej Kurek7d55dd22023-06-28 04:58:19 -0400124[dirname_to_malform]
Andrzej Kurek4a4f1ec2023-01-12 06:51:20 -0500125O=MALFORM_ME