blog.rootninja.com — No messing with the CA perl script or multiple openssl commands for requests, signings, password stripping, and catting keys/crts together. # openssl req -newkey rsa:1024 -x509 -nodes -out ldap-primary.pem -keyout ldap-primary.pem -days 3650