subjectAltName = DNS:*.$DOMAIN, DNS:$DOMAIN authorityKeyIdentifier = keyid, issuer basicConstraints = CA:FALSE keyUsage = digitalSignature, keyEncipherment extendedKeyUsage = serverAuth