The current script works as long as you can ignore the browser warnings. Wouldn't it be cool if you didn't need to do this? Jamie Nguyen has a [great blog explaining this](https://jamielinux.com/docs/openssl-certificate-authority/).