<?xml version="1.0" encoding="UTF-8"?>
<openca>
    <software_config>
        <prefix>@</prefix>
        <suffix>@</suffix>

        <!-- =============== -->
        <!-- general options -->
        <!-- =============== -->

        <option>
            <name>default_language</name>
            <value>C</value>
        </option>
        <option>
            <name>default_charset</name>
            <value>UTF-8</value>
        </option>
        <option>
            <name>cert_chars</name>
            <value>UTF8</value>
        </option>
	<option>
	    <name>default_web_username</name>
	    <value>admin</value>
	</option>
	<option>
	    <name>default_web_password</name>
	    <value>0DPiKuNIrrVmD8IUCuw1hQxNqZc</value>
	</option>
	<option>
            <!-- Name of your Organization (e.g, University of ... ) -->
            <name>organization</name>
            <value>Elwood CA</value>
        </option>
        <option>
            <name>ca_organization</name>
            <value>Elwood CA</value>
        </option>
        <option>
            <name>ca_locality</name>
            <value></value>
        </option>
        <option>
            <name>ca_state</name>
            <value>Bavaria</value>
        </option>
        <option>
            <!--
                please enter the ISO country code here
                DE, IT, PL, UK, US ...
                this country code is ALWAYS two characters long
              -->
            <name>ca_country</name>
            <value>DE</value>
        </option>
        <option>
            <name>sendmail</name>
            <value>/usr/lib/sendmail -n -t </value>
        </option>
        <option>
            <name>send_mail_automatic</name>
            <value>no</value>
        </option>
        <option>
            <name>service_mail_account</name>
            <value>elwood@agouros.de</value>
        </option>
        <option>
            <name>policy_link</name>
            <value>https://voyager/pki/pub/policy.html</value>
        </option>

        <!-- ======================== -->
        <!-- web server configuration -->
        <!-- ======================== -->
        <option>
            <name>httpd_protocol</name>
            <value>https</value>
        </option>
        <option>
            <name>httpd_host</name>
            <value>voyager</value>
        </option>
        <option>
            <name>httpd_port</name>
            <value>:443</value>
        </option>
        <option>
            <name>menu_logo_left</name>
            <value>
            <!--   Here you can put references to the logo, you can use
                   any html reference you want but please keep in mind that:
                   no <> are allowed, use instead &lt; and &gt; rispectively.

		   example:
                   &lt;img src="https://xyz.org/mylogo.jpg" alt="XYZ Logo"/&gt;
             -->
            </value>
        </option>
        <option>
            <name>menu_logo_right</name>
                &lt;a href="__HTDOCS_PREFIX__/thanks.html"&gt;
                   &lt;img src="__HTDOCS_PREFIX__/images/openca-logo.png" alt="OpenCA Logo"/&gt;
                &lt;/a&gt;
            <value></value>
        </option>
        <option>
            <name>CRLDistributionPoints</name>
            <value>
URI.1=http://ra/pki/pub/crl/cacrl.crl
            </value>
        </option>
        <option>
            <name>NS_CRLDistributionPoint</name>
            <value>http://voyager/pki/pub/crl/cacrl.crl</value>
        </option>

        <!-- ========================= -->
        <!-- ldap server configuration -->
        <!-- ========================= -->
        <option>
            <name>ldap_protocol</name>
            <value>3</value>
        </option>
        <option>
            <name>ldap_host</name>
            <value>ldapserver</value>
        </option>
        <option>
            <name>ldap_port</name>
            <value>389</value>
        </option>
        <option>
            <name>ldaproot</name>
            <value></value>
        </option>
        <option>
            <name>ldaprootpwd</name>
            <value></value>
        </option>
        <option>
            <name>useLDAP</name>
            <value>no</value>
        </option>
        <option>
            <name>update_ldap_automatic</name>
            <value>no</value>
        </option>

        <!-- ====================== -->
        <!-- database configuration -->
        <!-- ====================== -->
        <option>
            <name>dbmodule</name>
            <!-- you can use DB or DBI -->
            <value>DBI</value>
        </option>
        <option>
            <name>db_type</name>
            <value>Pg</value>
        </option>
        <option>
            <name>db_name</name>
            <value>openca</value>
        </option>
        <option>
            <name>db_host</name>
            <value>localhost</value>
        </option>
        <option>
            <name>db_port</name>
            <value>5432</value>
        </option>
        <option>
            <name>db_user</name>
            <value>openca</value>
        </option>
        <option>
            <name>db_passwd</name>
            <value>openca</value>
        </option>
        <option>
            <name>db_namespace</name>
            <value>openca</value>
        </option>

        <!-- ==================== -->
        <!-- module configuration -->
        <!-- ==================== -->
        <option>
            <name>module_shift</name>
            <!-- 8 bits are enough for IDs from 0 to 255    -->
            <!-- please remember that 0 is the ID of the CA -->
            <value>8</value>
        </option>
        <option>
            <name>ra_module_id</name>
            <value>1</value>
        </option>
        <option>
            <name>ldap_module_id</name>
            <value>2</value>
        </option>
        <option>
            <name>node_module_id</name>
            <value>3</value>
        </option>
        <option>
            <name>pub_module_id</name>
            <value>32</value>
        </option>
        <option>
            <name>scep_module_id</name>
            <value>33</value>
        </option>
        <option>
            <name>batch_module_id</name>
            <value>128</value>
        </option>

        <!-- =============================== -->
        <!-- configuration of relative paths -->
        <!-- =============================== -->

        <option>
            <name>batch_htdocs_url_prefix</name>
            <value>/pki/batch</value>
        </option>
        <option>
            <name>batch_cgi_url_prefix</name>
            <value>/cgi-bin/pki/batch</value>
        </option>
        <option>
            <name>ca_htdocs_url_prefix</name>
            <value>/pki/ca</value>
        </option>
        <option>
            <name>ca_cgi_url_prefix</name>
            <value>/cgi-bin/pki/ca</value>
        </option>
        <option>
            <name>node_htdocs_url_prefix</name>
            <value>/pki/node</value>
        </option>
        <option>
            <name>node_cgi_url_prefix</name>
            <value>/cgi-bin/pki/node</value>
        </option>
        <option>
            <name>ra_htdocs_url_prefix</name>
            <value>/pki/ra</value>
        </option>
        <option>
            <name>ra_cgi_url_prefix</name>
            <value>/cgi-bin/pki/ra</value>
        </option>
        <option>
            <name>ldap_htdocs_url_prefix</name>
            <value>/pki/ldap</value>
        </option>
        <option>
            <name>ldap_cgi_url_prefix</name>
            <value>/cgi-bin/pki/ldap</value>
        </option>
        <option>
            <name>pub_htdocs_url_prefix</name>
            <value>/pki/pub</value>
        </option>
        <option>
            <name>pub_cgi_url_prefix</name>
            <value>/cgi-bin/pki/pub</value>
        </option>
        <option>
            <name>scep_cgi_url_prefix</name>
            <value>/cgi-bin/pki/scep</value>
        </option>

        <!-- =============================== -->
        <!-- configuration of absolute paths -->
        <!-- =============================== -->

        <option>
            <name>batch_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/batch</value>
        </option>
        <option>
            <name>batch_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/batch</value>
        </option>
        <option>
            <name>ca_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/ca</value>
        </option>
        <option>
            <name>ca_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/ca</value>
        </option>
        <option>
            <name>node_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/node</value>
        </option>
        <option>
            <name>node_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/node</value>
        </option>
        <option>
            <name>ra_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/ra</value>
        </option>
        <option>
            <name>ra_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/ra</value>
        </option>
        <option>
            <name>ldap_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/ldap</value>
        </option>
        <option>
            <name>ldap_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/ldap</value>
        </option>
        <option>
            <name>pub_htdocs_fs_prefix</name>
            <value>/opt/openca/var/www/html/pki/pub</value>
        </option>
        <option>
            <name>pub_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/pub</value>
        </option>
        <option>
            <name>scep_cgi_fs_prefix</name>
            <value>/opt/openca/var/www/cgi-bin/pki/scep</value>
        </option>

        <!-- ===================== -->
        <!-- configuration of SCEP -->
        <!-- ===================== -->

        <option>
            <name>SCEP_RA_CERT</name>
            <value></value>
        </option>
        <option>
            <name>SCEP_RA_KEY</name>
            <value></value>
        </option>
        <option>
            <name>SCEP_RA_PASSWD</name>
            <value></value>
        </option>

        <!-- ===================== -->
        <!-- general configuration -->
        <!-- ===================== -->

        <option>
	    <name>USE_LOAS</name>
	    <value>yes</value>
	</option>
	<option>
            <name>prefix</name>
            <value>/opt/openca</value>
        </option>
        <option>
            <name>bindir</name>
            <value>/opt/openca/bin</value>
        </option>
        <option>
            <name>etc_prefix</name>
            <value>/opt/openca/etc/openca</value>
        </option>
        <option>
            <name>lib_prefix</name>
            <value>/opt/openca/lib/openca</value>
        </option>
        <option>
            <name>var_prefix</name>
            <value>/opt/openca/var/openca</value>
        </option>
        <option>
            <name>batch_prefix</name>
            <value>batch</value>
        </option>
        <option>
            <name>ca_prefix</name>
            <value>ca</value>
        </option>
        <option>
            <name>ldap_prefix</name>
            <value>ldap</value>
        </option>
        <option>
            <name>node_prefix</name>
            <value>node</value>
        </option>
        <option>
            <name>pub_prefix</name>
            <value>pub</value>
        </option>
        <option>
            <name>ra_prefix</name>
            <value>ra</value>
        </option>
        <option>
            <name>scep_prefix</name>
            <value>scep</value>
        </option>


        <!--   5. the node acts as public/scep and RA                       -->
            <option>
              <name>enroll_ca_certificate_states</name>
              <value></value>
            </option>
            <option>
              <name>enroll_certificate_states</name>
              <value></value>
            </option>
            <option>
              <name>enroll_crl_states</name>
              <value></value>
            </option>
            <option>
              <name>enroll_crr_states</name>
              <value></value>
            </option>
            <option>
              <name>enroll_csr_states</name>
              <value></value>
            </option>
            <option>
              <name>enroll_mail_states</name>
              <value></value>
            </option>
            <option>
              <name>receive_crr_states</name>
              <value></value>
            </option>
            <option>
              <name>receive_csr_states</name>
              <value></value>
            </option>
            <option>
              <name>download_ca_certificate_states</name>
              <value>VALID</value>
            </option>
            <option>
              <name>download_certificate_states</name>
              <value>VALID</value>
            </option>
            <option>
              <name>download_crl_states</name>
              <value>VALID</value>
            </option>
            <option>
              <name>download_crr_states</name>
              <value>ARCHIVED DELETED APPROVED</value>
            </option>
            <option>
              <name>download_csr_states</name>
              <value>ARCHIVED DELETED</value>
            </option>
            <option>
              <name>download_mail_states</name>
              <value>CRINS DEFAULT</value>
            </option>
            <option>
              <name>upload_crr_states</name>
              <value>APPROVED</value>
            </option>
            <option>
              <name>upload_csr_states</name>
              <value>APPROVED</value>
            </option>
        <option>
          <name>dataexchange_device_up</name>
          <value>/mnt/usb/caexch.tar</value>
        </option>
        <option>
          <name>dataexchange_device_down</name>
          <value>/mnt/usb/caexch.tar</value>
        </option>
        <option>
          <name>dataexchange_device_local</name>
          <value>/tmp/openca_local</value>
        </option>

    </software_config>
</openca>
