解决方法:
1. 使用自定义的openssl-ca.cnf
openssl req -new -key client.key -out client.csr -subj "/C=cn/ST=nanjing/L=nanjing/O=zte/OU=zte/CN=localhost" -config ./openssl-ca.cnf
2. 修改系统的/etc/pki/tls/openssl.cnf 注释掉[ v3_req ]段部分
# [ v3_req ]
# basicConstraints = CA:FALSE
# keyUsage = nonRepudiation, digitalSignature, keyEncipherment
# subjectAltName = @alt_names