Based off of this gist
I'm sick of typing the commands to self-sign these certs but I'm also way too lazy to setup proper PKI and ACME server. So instead I ssh into this server and do the needful each time, then rsync the key and crt LOL. All this crap is behind a VPN and the ssl is really just there so firefox will remember my passwords...
Why do we need faketime (apt install faketime
)? Because Apple.
And same with the fancy extendedKeyUsage
nonsense.