Генерируем сертификаты

cd  /etc/ssl/certs
openssl req -x509 -newkey rsa:2048 -keyout mail.pem -out mail.pem -days 9999 -nodes
...
Common Name (e.g. server FQDN or YOUR name) []: mail.domain.local
...
chmod 440 /etc/ssl/certs/mail.pem