openssl req -new -x509 -days 999999 \ -in public-csr.pem \ -key public.key \ -copy_extensions copy \ -out public.crt \ -addext "subjectAltName=DNS:josephwcarrillo.actor,DNS:*.josephwcarrillo.actor" \ -addext "basicConstraints=critical,CA:TRUE" \ -addext "keyUsage=critical,keyCertSign,cRLSign" #### mitmproxy command #### cat public.key public.crt > mitmproxy-ca.pem