The meaning of any SSL certificate (even self-signed) is that it uniquely identifies the server. So, if we have a generic cert distributed with our packaging, we break that. We could not even generate a cert at the "build" stage of our server, because that would be included in the packages. If anybody needs to run OpenERP with SSL, they will need to generate the certificate at the target server, possibly using ssl-cert.cfg as a sample. Also, the "ssl" directory under bin/ would confuse some pythonic code that had tried to "import ssl" (eg. urllib.py). bzr revid: p_christ@hol.gr-20101123135844-nr8k78qrmlyn19xb
90 lines
2.1 KiB
INI
90 lines
2.1 KiB
INI
# X.509 Certificate options
|
|
#
|
|
# DN options
|
|
|
|
# The organization of the subject.
|
|
organization = "Some organization."
|
|
|
|
# The organizational unit of the subject.
|
|
unit = "ERP dept."
|
|
|
|
# The locality of the subject.
|
|
# locality =
|
|
|
|
# The state of the certificate owner.
|
|
state = "State"
|
|
|
|
# The country of the subject. Two letter code.
|
|
country = BE
|
|
|
|
# The common name of the certificate owner.
|
|
cn = "Some company"
|
|
|
|
# A user id of the certificate owner.
|
|
#uid = "clauper"
|
|
|
|
# If the supported DN OIDs are not adequate you can set
|
|
# any OID here.
|
|
# For example set the X.520 Title and the X.520 Pseudonym
|
|
# by using OID and string pairs.
|
|
#dn_oid = "2.5.4.12" "Dr." "2.5.4.65" "jackal"
|
|
|
|
# This is deprecated and should not be used in new
|
|
# certificates.
|
|
# pkcs9_email = "none@none.org"
|
|
|
|
# The serial number of the certificate
|
|
serial = 001
|
|
|
|
# In how many days, counting from today, this certificate will expire.
|
|
expiration_days = 700
|
|
|
|
# X.509 v3 extensions
|
|
|
|
# A dnsname in case of a WWW server.
|
|
#dns_name = "www.none.org"
|
|
#dns_name = "www.morethanone.org"
|
|
|
|
# An IP address in case of a server.
|
|
#ip_address = "192.168.1.1"
|
|
|
|
# An email in case of a person
|
|
email = "none@none.org"
|
|
|
|
# An URL that has CRLs (certificate revocation lists)
|
|
# available. Needed in CA certificates.
|
|
#crl_dist_points = "http://www.getcrl.crl/getcrl/"
|
|
|
|
# Whether this is a CA certificate or not
|
|
#ca
|
|
|
|
# Whether this certificate will be used for a TLS client
|
|
#tls_www_client
|
|
|
|
# Whether this certificate will be used for a TLS server
|
|
tls_www_server
|
|
|
|
# Whether this certificate will be used to sign data (needed
|
|
# in TLS DHE ciphersuites).
|
|
#signing_key
|
|
|
|
# Whether this certificate will be used to encrypt data (needed
|
|
# in TLS RSA ciphersuites). Note that it is prefered to use different
|
|
# keys for encryption and signing.
|
|
encryption_key
|
|
|
|
# Whether this key will be used to sign other certificates.
|
|
#cert_signing_key
|
|
|
|
# Whether this key will be used to sign CRLs.
|
|
#crl_signing_key
|
|
|
|
# Whether this key will be used to sign code.
|
|
#code_signing_key
|
|
|
|
# Whether this key will be used to sign OCSP data.
|
|
#ocsp_signing_key
|
|
|
|
# Whether this key will be used for time stamping.
|
|
#time_stamping_key
|