Just some quick notes about openssl certificate workflow.

Checking certs

Reading cert

openssl s_client -connect localhost:smtps

Checking if cert is expired

openssl s_client -connect localhost:smtps | openssl x509 -dates

Creating certs

key and crt

openssl req -nodes -x509 -newkey rsa:4096 -sha512 -keyout exim.key -out exim.crt -days 365

pem

openssl req -nodes -x509 -newkey rsa:4096 -sha512 -keyout exim.pem -out exim.pem -days 365

CSR

openssl req -new -sha256 -key exim.key -out exim_csr.pem