openssl genrsa -out /etc/ssl/private/ca.key 1024
openssl req -new -x509 -days 365 -key /etc/ssl/private/ca.key -out /etc/ssl/private/ca.crt
mkdir -p -m665 /etc/mail/certs
chown root:postfix /etc/mail/certs
chmod 660 /etc/mail/certs
openssl req -new -nodes -out /etc/mail/certs/req.pem -keyout /etc/mail/certs/cert.pem
openssl x509 -req -CA /etc/ssl/private/ca.crt -CAkey /etc/ssl/private/ca.key -days 365 -in /etc/mail/certs/req.pem -out /tmp/cert.pem -CAcreateserial
chmod 600 /etc/mail/certs/cert.pem
chown root:0 /etc/mail/certs/cert.pem
cat /tmp/cert.pem >> /etc/mail/certs/cert.pem