I absolutely can. I know that project I listed has 0 documentation, but I should rip out the code and move it to another repo with a README.
The short of it is that I run the following. (I know this repo has our public keys, but if you clone it you can totally run this as well to see what's going on).
./bin/root-ca.sh
./bin/tls-ca.sh
./bin/client.sh
The first command will create the Root Certificate Authority in your tiered system. The second one will create a TLS Certificate Authority underneath the Root. This TLS CA is for issuing certificates (like browser client certificates, or email S/MIME certificates). Finally, the last script will walk you through creating one of these client certs.
The client.sh script will generate a .p12 file that you can import into Keychain or your browser's certificate store. The only other step is to import the Root certificate (mine is TeachBoostRootCA.crt in the ca folder) into Keychain and/or your browser.
If you're curious, take a look at the config file in the top level directory. This has all of the naming conventions my repo uses but if you clone this, clear the 'ca', 'certs', and 'crl' folders, then you can have free reign on running your own Certificate Authority. The scripts will walk you through everything but if you have any questions don't hesitate to open a GH issue on that repo and I'll get back to you there.