[req] default_bits = 2048 prompt = no default_md = sha256 req_extensions = req_ext distinguished_name = dn x509_extensions = v3_ca # The extentions to add to the self signed cert req_extensions = v3_req x509_extensions = usr_cert [ dn ] C=IL ST=Israel L=TLV O=Onyx OU=CyberArk CN=conjur-proxy-nginx [ usr_cert ] basicConstraints=CA:FALSE nsCertType = client, server, email keyUsage = nonRepudiation, digitalSignature, keyEncipherment extendedKeyUsage = serverAuth, clientAuth, codeSigning, emailProtection nsComment = "OpenSSL Generated Certificate" subjectKeyIdentifier=hash authorityKeyIdentifier=keyid,issuer [ v3_req ] extendedKeyUsage = serverAuth, clientAuth, codeSigning, emailProtection basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment [ v3_ca ] subjectAltName = @alt_names [ alt_names ] DNS.1 = localhost DNS.2 = conjur-proxy-nginx IP.1 = 127.0.0.1