--- a/hs20/server/ca/setup.sh
+++ b/hs20/server/ca/setup.sh
@@ -3,7 +3,7 @@
 if [ -z "$OPENSSL" ]; then
     OPENSSL=openssl
 fi
-export OPENSSL_CONF=$PWD/openssl.cnf
+export OPENSSL_CONF=/usr/share/hs20/ca/openssl.cnf
 PASS=whatever
 if [ -z "$DOMAIN" ]; then
     DOMAIN=w1.fi
@@ -83,10 +83,10 @@ then
 fi
 
 # Set the passphrase and some other common config accordingly.
-cat openssl-root.cnf | sed "s/@PASSWORD@/$PASS/" \
+cat /usr/share/hs20/ca/openssl-root.cnf | sed "s/@PASSWORD@/$PASS/" \
  > my-openssl-root.cnf
 
-cat openssl.cnf | sed "s/@PASSWORD@/$PASS/" |
+cat /usr/share/hs20/ca/openssl.cnf | sed "s/@PASSWORD@/$PASS/" |
 sed "s,@OCSP_URI@,$OCSP_URI," |
 sed "s,@LOGO_URI@,$LOGO_URI," |
 sed "s,@LOGO_HASH1@,$LOGO_HASH1," |