If you do not already have a Public Key Infrastructure (PKI), the Open vSwitch project provides an application called ovs-pki that can create the certificates and private keys required by TLS.
To use this application:
$ openssl version OpenSSL 1.0.1e-fips 11 Feb 2013 $ ovs-pki --version ovs-pki (Open vSwitch) 2.3.2