mirror of
https://github.com/QuasarApp/openssl.git
synced 2025-04-29 11:14:36 +00:00
rfc2606 compliant example domains for x509v3_config.pod
Reviewed-by: Ben Kaduk <kaduk@mit.edu> Reviewed-by: Tomas Mraz <tomas@openssl.org> (Merged from https://github.com/openssl/openssl/pull/14210)
This commit is contained in:
parent
125107e8ea
commit
458d168cd4
@ -79,8 +79,8 @@ section. In this example:
|
|||||||
subjectAltName = @alt_section
|
subjectAltName = @alt_section
|
||||||
|
|
||||||
[alt_section]
|
[alt_section]
|
||||||
email = steve@here
|
email = steve@example.com
|
||||||
email = steve@there
|
email = steve@example.org
|
||||||
|
|
||||||
will only recognize the last value. To specify multiple values append a
|
will only recognize the last value. To specify multiple values append a
|
||||||
numeric identifier, as shown here:
|
numeric identifier, as shown here:
|
||||||
@ -89,8 +89,8 @@ numeric identifier, as shown here:
|
|||||||
subjectAltName = @alt_section
|
subjectAltName = @alt_section
|
||||||
|
|
||||||
[alt_section]
|
[alt_section]
|
||||||
email.1 = steve@here
|
email.1 = steve@example.com
|
||||||
email.2 = steve@there
|
email.2 = steve@example.org
|
||||||
|
|
||||||
The syntax of raw extensions is defined by the source code that parses
|
The syntax of raw extensions is defined by the source code that parses
|
||||||
the extension but should be documened.
|
the extension but should be documened.
|
||||||
@ -237,13 +237,13 @@ using the syntax in L<ASN1_generate_nconf(3)>.
|
|||||||
|
|
||||||
Examples:
|
Examples:
|
||||||
|
|
||||||
subjectAltName = email:copy, email:my@other.address, URI:http://my.url.here/
|
subjectAltName = email:copy, email:my@example.com, URI:http://my.example.com/
|
||||||
|
|
||||||
subjectAltName = IP:192.168.7.1
|
subjectAltName = IP:192.168.7.1
|
||||||
|
|
||||||
subjectAltName = IP:13::17
|
subjectAltName = IP:13::17
|
||||||
|
|
||||||
subjectAltName = email:my@other.address, RID:1.2.3.4
|
subjectAltName = email:my@example.com, RID:1.2.3.4
|
||||||
|
|
||||||
subjectAltName = otherName:1.2.3.4;UTF8:some other identifier
|
subjectAltName = otherName:1.2.3.4;UTF8:some other identifier
|
||||||
|
|
||||||
@ -292,9 +292,9 @@ B<caRepository> (CA Repository).
|
|||||||
|
|
||||||
Examples:
|
Examples:
|
||||||
|
|
||||||
authorityInfoAccess = OCSP;URI:http://ocsp.my.host/,caIssuers;URI:http://my.ca/ca.cer
|
authorityInfoAccess = OCSP;URI:http://ocsp.example.com/,caIssuers;URI:http://myca.example.com/ca.cer
|
||||||
|
|
||||||
authorityInfoAccess = OCSP;URI:http://ocsp.my.host/
|
authorityInfoAccess = OCSP;URI:http://ocsp.example.com/
|
||||||
|
|
||||||
=head2 CRL distribution points
|
=head2 CRL distribution points
|
||||||
|
|
||||||
@ -338,9 +338,9 @@ Only one of B<fullname> or B<relativename> should be specified.
|
|||||||
|
|
||||||
Simple examples:
|
Simple examples:
|
||||||
|
|
||||||
crlDistributionPoints = URI:http://myhost.com/myca.crl
|
crlDistributionPoints = URI:http://example.com/myca.crl
|
||||||
|
|
||||||
crlDistributionPoints = URI:http://my.com/my.crl, URI:http://oth.com/my.crl
|
crlDistributionPoints = URI:http://example.com/myca.crl, URI:http://example.org/my.crl
|
||||||
|
|
||||||
Full distribution point example:
|
Full distribution point example:
|
||||||
|
|
||||||
@ -348,7 +348,7 @@ Full distribution point example:
|
|||||||
crlDistributionPoints = crldp1_section
|
crlDistributionPoints = crldp1_section
|
||||||
|
|
||||||
[crldp1_section]
|
[crldp1_section]
|
||||||
fullname = URI:http://myhost.com/myca.crl
|
fullname = URI:http://example.com/myca.crl
|
||||||
CRLissuer = dirName:issuer_sect
|
CRLissuer = dirName:issuer_sect
|
||||||
reasons = keyCompromise, CACompromise
|
reasons = keyCompromise, CACompromise
|
||||||
|
|
||||||
@ -394,7 +394,7 @@ Example:
|
|||||||
issuingDistributionPoint = critical, @idp_section
|
issuingDistributionPoint = critical, @idp_section
|
||||||
|
|
||||||
[idp_section]
|
[idp_section]
|
||||||
fullname = URI:http://myhost.com/myca.crl
|
fullname = URI:http://example.com/myca.crl
|
||||||
indirectCRL = TRUE
|
indirectCRL = TRUE
|
||||||
onlysomereasons = keyCompromise, CACompromise
|
onlysomereasons = keyCompromise, CACompromise
|
||||||
|
|
||||||
@ -437,8 +437,8 @@ Example:
|
|||||||
|
|
||||||
[polsect]
|
[polsect]
|
||||||
policyIdentifier = 1.3.5.8
|
policyIdentifier = 1.3.5.8
|
||||||
CPS.1 = "http://my.host.name/"
|
CPS.1 = "http://my.host.example.com/"
|
||||||
CPS.2 = "http://my.your.name/"
|
CPS.2 = "http://my.your.example.com/"
|
||||||
userNotice.1 = @notice
|
userNotice.1 = @notice
|
||||||
|
|
||||||
[notice]
|
[notice]
|
||||||
@ -483,7 +483,7 @@ Examples:
|
|||||||
|
|
||||||
nameConstraints = permitted;IP:192.168.0.0/255.255.0.0
|
nameConstraints = permitted;IP:192.168.0.0/255.255.0.0
|
||||||
|
|
||||||
nameConstraints = permitted;email:.somedomain.com
|
nameConstraints = permitted;email:.example.com
|
||||||
|
|
||||||
nameConstraints = excluded;email:.com
|
nameConstraints = excluded;email:.com
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user