Hopefully Let's Encrypt (and ACME in general) and similar efforts will help to alleviate that issue.
Let's Encrypt in particular seems to be more geared toward websites, but I actually did manage to put it to use rather trivially on my mailserver (which previously used self-signed certs) thanks to 'acme-client' on OpenBSD.
Let's Encrypt in particular seems to be more geared toward websites, but I actually did manage to put it to use rather trivially on my mailserver (which previously used self-signed certs) thanks to 'acme-client' on OpenBSD.