[ req ]
 default_bits           = 2048
 distinguished_name     = req_distinguished_name
 x509_extensions        = v3_req
 req_extensions         = v3_req
 prompt                 = no

 dirstring_type = nobmp

 [ req_distinguished_name ]
 C                      = DE
 ST                     = Nordrhein Westfalen
 L                      = Bochum
 O                      = Edgeless Systems GmbH
 CN                     = Constellation Testing UEFI CA 2022

 [ v3_req ]
 subjectKeyIdentifier = hash
 basicConstraints     = critical,CA:true
 keyUsage             = digitalSignature,keyCertSign,cRLSign