openssl genrsa -des3 -out ca.keyopenssl req -new -x509 -days 1825 -key ca.key -out ca.crtopenssl genrsa -des3 -out user.key 4096openssl req -new -key user.key -out user.csropenssl x509 -req -days 1825 -in user.csr -CA ca.crt -CAkey ca.key -set_serial 01 -out user.crtopenssl pkcs12 -export -out user.pfx -inkey user.key -in user.crt -certfile ca.crtssl_client_certificate /etc/nginx/client_certs/ca.crt; ssl_verify_client optional;