14th December 2005
The only values I entered were the country code and state. I entered '.' for others. It did not complain about the first two steps:

STEP 0: Decide the signature algorithm used for certificates
The generated X.509 certificates can contain either
RSA or DSA based ingredients. Select the one you want to use.
Signature Algorithm ((R)SA or (D)SA) [R]:
__________________________________________________ ____________________

STEP 1: Generating RSA private key for CA (1024 bit) [ca.key]
1403621 semi-random bytes loaded
Generating RSA private key, 1024 bit long modulus
e is 65537 (0x10001)
__________________________________________________ ____________________

STEP 2: Generating X.509 certificate signing request for CA [ca.csr]
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
1. Country Name (2 letter code) [XY]:US
2. State or Province Name (full name) [Snake Desert]:Virginia
3. Locality Name (eg, city) [Snake Town]:.
4. Organization Name (eg, company) [Snake Oil, Ltd]:.
5. Organizational Unit Name (eg, section) [Certificate Authority]:.
6. Common Name (eg, CA name) [Snake Oil CA]:.
7. Email Address (eg, name@FQDN) [ca@snakeoil.dom]:.
8. Certificate Validity (days) [365]:.
__________________________________________________ ____________________

STEP 3: Generating X.509 certificate for CA signed by itself [ca.crt]
Certificate Version (1 or 3) [3]:
bad number of days
