生成自签发证书
openssl req -newkey rsa:2048 -nodes -keyout /root/haproxy.key -x509 -days 3650 -out /root/haproxy.crt
证书格式转换 (pfx to crt)
openssl pkcs12 -in /etc/ssl/certs/longterm.pfx -clcerts -nokeys -out /etc/ssl/certs/longterm.crt
证书格式转换 (pfx to key)
openssl pkcs12 -in /etc/ssl/certs/longterm.pfx -nocerts -nodes -out /etc/ssl/certs/longterm.key
合并crt和key成pem
cat xxx.crt xxx.key | tee xxx.pem