dns interceptors

Yes. Easy rsa is the way to go.

They are normal certs. Check the scripts if you want to roll your own openssl wrapper scripts.