This is not part of the official process.
# Creating a CA key:
# req -new -x509 - New x509-es request.
# -nodes - Private key do not be secured by passphrase.
# -days 3650 - 10*365=3650 day, it means 10 years.
# -newkey rsa:2048 -sha256 - 2048-as RSA, with SHA256