One last question and I think I'll have what I need. (And yes I am very new
to openssl.)

I was able to produce the self signed Root CA, the intermediate CA, and
then sign my server device CA with the intermediate CA.  I was able to use
openssl verify to make sure my server certificate was OK.

I used "openssl x509 -in cert-name.pem -text -noout" to inspect all three
pem files. I see that I ended up a signature algorithm of edcsa-with-SHA1
when I wanted ecdsa-with-SHA384 in each of them.

Here are the commands I used. Trying to figure out how to change them to
make the ROOT CA. Intermediate CA  and Device Certificate have SHA384 as
the signature algorithm instead of SHA1. After I get that; I think I am set.

Generate Key and Self Signed Root CA
a) openssl ecparam -out ca.key -name secp384r1 -genkey

b) openssl req -new -x509 -days 3650 -key ca.key -out ca.crt

c) openssl x509  -in  ca.crt -out ca.pem

d) openssl x509 -in ca.pem -text -noout

        Version: 3 (0x2)
        Serial Number:
    Signature Algorithm: ecdsa-with-SHA1    <<<<< Want ecdsa-with-SHA384

Generate Key and Intermediate Cert
a) openssl ecparam -out ca-int.key -name secp384r1 -genkey

b) openssl req -new -key ca-int.key -out ca-int.csr -subj "/CN="

c) openssl x509 -req -days 3650 -in ca-int.csr -CA ca.crt -CAkey ca.key
-set_serial 01 -out ca-int.crt

d) openssl x509 -in ca-int.crt -text -noout

        Version: 1 (0x0)
        Serial Number: 1 (0x1)
    Signature Algorithm: ecdsa-with-SHA1    <<<< Want ecdsa-with-SHA384

Sign Server CSR from device
a) openssl x509 -req -days 3650 -in server.csr -CA ca-int.crt -CAkey
ca-int.key -set_serial 01 -out server.pem

b) openssl x509 -in server.pem -text -noout
        Version: 1 (0x0)
        Serial Number: 1 (0x1)
    Signature Algorithm: ecdsa-with-SHA1    <<<< Want ecdsa-with-SHA384



