xref: /freebsd/contrib/pam-krb5/ci/files/mit/extensions.kdc (revision bf6873c5786e333d679a7838d28812febf479a8a)
1[kdc_cert]
2basicConstraints=CA:FALSE
3keyUsage=nonRepudiation,digitalSignature,keyEncipherment,keyAgreement
4extendedKeyUsage=1.3.6.1.5.2.3.5
5subjectKeyIdentifier=hash
6authorityKeyIdentifier=keyid,issuer
7issuerAltName=issuer:copy
8subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:kdc_princ_name
9
10[kdc_princ_name]
11realm=EXP:0,GeneralString:${ENV::REALM}
12principal_name=EXP:1,SEQUENCE:kdc_principal_seq
13
14[kdc_principal_seq]
15name_type=EXP:0,INTEGER:1
16name_string=EXP:1,SEQUENCE:kdc_principals
17
18[kdc_principals]
19princ1=GeneralString:krbtgt
20princ2=GeneralString:${ENV::REALM}
21