basicConstraints = CA:FALSE keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment authorityKeyIdentifier = keyid,issuer subjectAltName = @alt_names [alt_names] DNS.1 = ${ENV::HOST_FQDN}