+#keytool -importcert -keystore server.jks -storepass changeit \
+# -alias CA -file CA/cacert.pem
+
+openssl req -new -newkey rsa:4096 -extensions server_ext -days 365 \
+ -subj $SERVER_DN \
+ -keyout node_key.pem -passout pass:demo -out node_csr.pem
+openssl ca -batch -passin pass:demo -in node_csr.pem -out node_crt.pem
+cat node_crt.pem CA/cacert.pem > node.pem
+openssl pkcs12 -export -passin pass:demo -passout pass:demo \
+ -name "node" -inkey node_key.pem -in node.pem \
+ -out node.p12
+