Some stuff related to certificates
openssl genrsa -out rootCA.key 4096
openssl req -x509 -new -nodes -key rootCA.key -sha256 -days 3650 -out rootCA.crt
openssl genrsa -des3 -out fehervari-router.key 4096
openssl req -new -key fehervari-router.key -out fehervari-router.csr -addext "subjectAltName = IP:192.168.88.1"
openssl x509 -req -days 3650 -in fehervari-router.csr -CA rootCA.crt -CAkey rootCA.key -set_serial 01 -out fehervari-router.crt -extensions v3_ca -extfile <(echo "[v3_ca]"; echo "extendedKeyUsage=serverAuth"; echo "subjectAltName=IP:192.168.88.1")
SYSNAME=xxx
DOMAIN=yyy
openssl x509 \
-req \
-days 3650 \
-in "${SYSNAME}.csr" \
-CA rootCA.crt \
-CAkey rootCA.key \
-set_serial 01 \
-out "${SYSNAME}.crt" \
-extensions v3_ca \
-extfile <(echo "[v3_ca]"; echo "extendedKeyUsage=serverAuth"; echo "subjectAltName=DNS:${DOMAIN}")
/certificate import file-name=fehervari-router.crt
/certificate import file-name=fehervari-router.key
/ip service set www-ssl certificate=fehervari-router.crt_0
/ip service enable www-ssl
/ip service disable www