All docs are wrong (applies to v5.21) do this with openssl: openssl genrsa -out mikroTik.ca.key.pem 2048 openssl req -new -x509 -nodes -days 9999 -key mikroTik.ca.key.pem -out mikroTik.ca.cert.pem Drag and drop both files into winBox, then import both files. Cert will show up with KR flag. Use it fo...