Самоподписанный сертификат с SAN

openssl genrsa -des3 -out example.com.key 2048
openssl req -new -key example.com.key -out example.com.csr
cp example.com.key example.com.key.org
openssl rsa -in example.com.key.org -out example.com.key
touch v3.ext
subjectKeyIdentifier   = hash
authorityKeyIdentifier = keyid:always,issuer:always
basicConstraints       = CA:TRUE
keyUsage               = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment, keyAgreement, keyCertSign
subjectAltName         = DNS:example.com, DNS:*.example.com
issuerAltName          = issuer:copy
openssl x509 -req -in example.com.csr -signkey example.com.key -out example.com.crt -days 3650 -sha256 -extfile v3.ext