MyNixOS website logo
option-set

services.cfssl

Showing entries 1-23 out of 23.
Address to bind
services.cfssl.caNixOS option
CA used to sign the new certificate -- accepts '[file:]fname' or 'env:varname'
Path to root certificate store
CA private key -- accepts '[file:]fname' or 'env:varname'
Path to configuration file
The work directory for CFSSL.If left as the default value this directory will automatically be cre…
Certificate db configuration file
Whether to enable the CFSSL CA api-server
Path to intermediate certificate store
Intermediates directory
Log level (0 = DEBUG, 5 = FATAL)
Metadata file for root certificate presence
Mutual TLS - require clients be signed by this CA
Mutual TLS - client certificate to call remote instance requiring client certs
Mutual TLS - client key to call remote instance requiring client certs
Mutual TLS - regex for whitelist of allowed client CNs
Port to bind
Remote CFSSL server
Certificate for OCSP responder
Private key for OCSP responder certificate
Other endpoint's CA to set up TLS protocol
Other endpoint's CA private key
CAs to trust for remote TLS requests