sudo(8) openssl(1ssl) req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/server.key -out /etc/ssl/certs/server.crt
execute a command as another user
OpenSSL command line tool
source manpages: sudoopenssl