# Intermediate Root CA
[ req ]
default_md = sha256
utf8 = yes
string_mask = utf8only
prompt = no
distinguished_name = req_dn
req_extensions = req_ext
x509_extensions = v3_req_ext
[ req_dn ]
0.domainComponent = "COM"
1.domainComponent = "EXAMPLE"
organizationalUnitName = "Intermediate Certificate Authority"
commonName = "intermediate-ca.example.com"
emailAddress = "intermediate-ca@example.com"
[ req_ext ]
subjectKeyIdentifier = hash
#authorityKeyIdentifier = keyid:always,issuer:always
basicConstraints = critical,CA:true
keyUsage = critical,keyCertSign,cRLSign
[ v3_req_ext ]
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer:always
basicConstraints = critical,CA:true
keyUsage = critical,keyCertSign,cRLSign
subjectAltName = email:intermediate-ca@example.com
issuerAltName = issuer:copy