#!/bin/sh AKID="`cat nssdb/ca_signing.skid`" echo "AKID: ${AKID}" OCSP="`cat nssdb/ocsp_url`" echo "OCSP: ${OCSP}" echo -e "y\n${AKID}\n\n\n\n2\n7\n${OCSP}\n\n\n\n" | \ certutil -C \ -d nssdb \ -f nssdb/password.txt \ -m $RANDOM \ -a \ -i nssdb/sslserver.csr \ -o nssdb/sslserver.crt \ -c "ca_signing" \ -3 \ --extAIA \ --keyUsage critical,dataEncipherment,keyEncipherment,digitalSignature,nonRepudiation \ --extKeyUsage serverAuth certutil -A -d nssdb -n "sslserver" -i nssdb/sslserver.crt -t ",," openssl x509 -text -noout -in nssdb/sslserver.crt