https://github.com/FiloSottile/mkcert
It's in pure Go instead of using OpenSSL, and it works with Windows, macOS and Firefox, too.
https://github.com/FiloSottile/mkcert
It's in pure Go instead of using OpenSSL, and it works with Windows, macOS and Firefox, too.
I've added a link to your project in my README.md file.
Initially they used to come as a goodies with OpenVPN, but they are now provided as a standalone project.
There are already packaged and available in most distributions (easy-rsa package under Debian for example).
There are probably a little bit more complex to use, but it's far from horrible, and it's quite battle tested.
Also, Go's TLS library is missing some important features, like decrypting most varieties of private keys.
I use Go's TLS library, but I don't think it's necessary "better" than openssl, though it's certainly more convenient.