| 1 | basicConstraints = CA:FALSE |
| 2 | authorityKeyIdentifier = keyid, issuer |
| 3 | keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment |
| 4 | extendedKeyUsage = serverAuth, clientAuth |
| 5 | subjectAltName = @alt_names |
| 6 | |
| 7 | [alt_names] |
| 8 | DNS.1 = localhost |
| 9 | DNS.2 = pebble |
| 10 | IP.1 = 127.0.0.1 |