suffers from a number of problems:
- problems with certificate revocation as reported by James Boyle
- only offers old/broken hashes
- passes config vars in the environment to openssl(1), which is
not supported by libressl
- warnings with current versions of perl
If you're looking for a gui tool for a private CA, you might like to try
the xca package instead. (For a non-gui toolkit, cloudflare's cfssl might
be of interest; it's not in ports though).