Update 2023-09-17: Well, hello Hacker News! (comments) I also added nameConstraints to the cacert.sh to make this even better than before. Yay, constructive feedback! Problem statement Anyone wanting their own X509 cert these days has free-beer alternatives like ZeroSSL or Let’s Encrypt. But, what if it’s just for internal services, some of them even cut off from the ‘Net? And more importantly, wh