Bug Fixes
- CA certificates now include proper X.509 extensions (#2)
basicConstraints=critical,CA:TRUE- Identifies certificate as a CA (RFC 5280 requirement)keyUsage=critical,keyCertSign,crlSign- Allows signing certificates and CRLssubjectKeyIdentifier=hash- Helps identify certificates issued by this CA
This fixes certificate chain validation failures in TLS clients and Java truststores when using CA certificates created by PKI Manager.