Travis wrote:
> Hello,
> Recently I set up certificates for my server's SSL, SMTP, IMAP, XMPP,
> and OpenVPN services.  Actually, I created my own CA for some of the
> certificates, and in other cases I used self-signed.  It took me
> substantially more time than I had anticipated, and I'm left with
> feelings of unease.

odd. the openssl installations I am familiar with came with example
config files that were perfectly functional, took me about ten minutes
to figure out what needed doing purely from the man pages and the
example config.

if ten minutes is too long, just go with xca
( which does it all in a nice,
pretty gui for you. A few distros (suse, for example) also have a gui
for certificate issuing in their central admin tool.

