[ ca ]
default_ca = exampleca
 
[ exampleca ]
dir              = /opt/exampleca
certificate       = $dir/cacert.pem
database         = $dir/index.txt
new_certs_dir    = $dir/certs
private_key      = $dir/private/cakey.pem
serial           = $dir/serial
 
default_crl_days = 7
default_days     = 365
default_md       = md5
 
policy           = exampleca_policy
x509_extensions  = certificate_extensions
 
[ exampleca_policy ]
commonName             = supplied
stateOrProvinceName    = supplied
countryName            = supplied
emailAddress           = supplied
organizationName       = supplied
organizationalUnitName = optional
 
[ certificate_extensions ]
basicConstraints = CA:false
