don't copy issuer to authorityKeyIdentifier

issuer contains the CA' serial number, thus making CA rollover trickier (you'd
need to issue a new cert with the same serial). Having only keyid allows for
easier CA rollover.
......@@ -3,7 +3,7 @@ nsCertType = %(usage)s
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth, serverAuth
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid, issuer:always
authorityKeyIdentifier = keyid:always
subjectAltName = @subject_alt_name
issuerAltName = issuer:copy
crlDistributionPoints = @cdp_section
