The parentCert is the CA that I used to sign the client's certs. I will try those extensions as soon as possible and get back with you.
'basicConstraints' => 'CA:TRUE,pathlen:1''subjectKeyIdentifier' => 'hash''authorityKeyIdentifier' => 'keyid,issuer:always''keyUsage' => 'cRLSign,keyCertSign'