rpm -ivh nss-tools
certutil -N -d <database path>
Create a CSR with subject CN=<common name>,O=<realm>, for example:
certutil -R -d <database path> -a -g <key size> -s 'CN=<common name>,O=DOMAIN.COM'
mkcert
Advertising: