

Openssl can do everything.
That’s right, but instead of the word derived we use “issued”
Correct certs get old by design, they can also be revoked. As another commenter mentioned the biggest pain is actually in the redistribution of these end certificates. In enterprise this is all managed usually with the same software they use for deployment or have auto enrollment configured.
You should find tons of guides just take it slow to understand it all. Understanding certificates in depth is a rare and good skill to have. Most sysadmins I come across are scared to death of certificates.










I remember one time in the early 90s we fried my friends dad’s ram in a proprietary IBM by mixing with another computer. Nowadays I understand it was likely a voltage mismatch. It cost him thousands. He was Scottish and I have never seen a man turn so red in my life.