1 # This template file specifies that the certificate is a certificate
2 # authority that will be used to sign other certificates, and
3 # certificate revocations. Set additional properties (e.g. a CRL URI)
6 # Certificate authority template
7 organization = "Example"
8 cn = "Your CA name here"
11 # This CA can not issue subsidiary CAs
17 # Signs certificates and certificate revocation lists
21 # Name constraints (recommended); new in GnuTLS 3.3.x
22 # Setting this will allow this CA to only issue
23 # certificates for this domain
24 nc_permit_dns = "example.com"
25 #nc_exclude_dns = "test.example.com"