had no errors with the mmc, by selecting “show all files” and selecting the rootSSL.pem file.
Using Windows 10, powershell, when creating the new certificate using rootSSL certificate i did need to create a seperate -ext file called ‘v3.ext’:
keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment
final command looked like this:
-CA rootSSL.pem -CAkey rootSSL.key -CAcreateserial