Hi,
maybe there is a bug in creating a CA:
there should be a
Certificate:
Signature Algorithm:
X509v3 extensions:
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
or something like this.
When I create a CA in opnSense, there is no "X509v3 Key Usage".