Generate a certificate signing request (this generates the privkey.pem and includes the public key in the csr):
openssl req -new -nodes > req.csrThen convert the public key to a public certificate and sign it with its own private key.
openssl x509 -req -in req.csr -signkey privkey.pem -out cert.pemIf you want, you can also encrypt the private key:
openssl rsa -in privkey.pem -aes256 -out key.pem