$ openssl req -x509 -newkey rsa:2048 -keyout foo.key \
-out foo.crt -days 3600 -nodes -config conf
$ openssl x509 -noout -text -in foo.pem
ssl_certificate /etc/felix/ssl/foo.crt;
ssl_certificate_key /etc/felix/ssl/foo.key;
listen 443 ssl;
proxy_set_header X-Forwarded-Proto $scheme;