Show HN: A tool for creating custom TLS CA bundles
mkcert.org
mkcert.org
Or you could just download debian's ca-certificates package and cat together all the .crt files you choose into a .pem. Much quicker & simpler.
But seriously, great idea, but wouldn't this be better as a command-line tool installable via a package manager? At least then it could be audited.
Edit: what if this were built into Firefox? Could the certificate manager accommodate some UI improvements and an export feature?
As for self-hosting, I think anyone who wants to deploy mkcert in anger should self-host, and I believe I've made it trivial to do that. There are some steps I can still take to improve this: I want to pin Mozilla's cert in the client so that it can't be MITM'd, for example.