Prepare directory structure and stating files
mkdir -p {root-ca,sub-ca,signing-ca,app-ca}/{certs,crl,csr,db,private}
touch {root-ca,sub-ca,signing-ca,app-ca}/db/index
openssl rand -hex 16 > {root-ca,sub-ca,signing-ca,app-ca}/db/serial
echo 1000 > {root-ca,sub-ca,signing-ca,app-ca}/db/crlnumber
Create csr
openssl req -new \