[Version] Signature="$Windows NT$" [NewRequest] ; CN replace with your registered business name ; OU replace with your digital ; For O, replace with ; For C, replace with...... Subject="CN=Donau Sandbank AG, OU=OU ID, O=Donau Sandbank AG, C=DE" KeySpec = 1 ; KeyLength minimum is 3072 KeyLength = 3072 HashAlgorithm = sha256 Exportable = FALSE MachineKeySet = TRUE SMIME = False PrivateKeyArchive = FALSE UserProtected = FALSE UseExistingKeySet = FALSE ProviderName = "Microsoft RSA SChannel Cryptographic Provider" ProviderType = 12 RequestType = PKCS10 KeyUsage = 0xa0 [EnhancedKeyUsageExtension] OID=1.3.6.1.5.5.7.3.2 ; this is for Client Authentication [Extensions] 2.5.29.17 = "{text}" ; For SAN (Subject Alternative Name) extension "DNS", only leave the required. One entry of "dns=" must correspond to Subject = "CN=myserver.domain.any" (e.g.: _continue_ = "dns = myserver.domain.any&") - remove the example entries! _continue_ = "DNS=instance1.donau-sandbank.de&" ; The SAN (Subject Alternative Name) extension rfc822 "EMail" sets the notification eMail address receiving lifecyle notification emails (request for revocation, certificate expiration, etc.). It is strongly recommend to set this value to the address of a group mailbox or mailing list and NOT to an address of individual person. _continue_ =  "EMail=cryptoservices@donau-sandbank.de&"