openssl.ss.cnf :

basicConstraints=CA:FALSE
subjectAltName=DNS:*.domain.tld
extendedKeyUsage=serverAuth

Request generation

openssl req -new -key bump.key -extensions v3_ca -out MyRequest.csr

Certificat generation

openssl x509 -req -in MyRequest.csr -CA bump.crt -CAkey bump.key -CAcreateserial -extfile openssl.ss.cnf -out wc_murcier.fun.crt -days 365 -sha256