1[kdc_cert] 2basicConstraints=CA:FALSE 3keyUsage=nonRepudiation,digitalSignature,keyEncipherment,keyAgreement 4extendedKeyUsage=1.3.6.1.5.2.3.5 5subjectKeyIdentifier=hash 6authorityKeyIdentifier=keyid,issuer 7issuerAltName=issuer:copy 8subjectAltName=otherName:1.3.6.1.5.2.2;SEQUENCE:kdc_princ_name 9 10[kdc_princ_name] 11realm=EXP:0,GeneralString:${ENV::REALM} 12principal_name=EXP:1,SEQUENCE:kdc_principal_seq 13 14[kdc_principal_seq] 15name_type=EXP:0,INTEGER:1 16name_string=EXP:1,SEQUENCE:kdc_principals 17 18[kdc_principals] 19princ1=GeneralString:krbtgt 20princ2=GeneralString:${ENV::REALM} 21