Either provide copy&paste examples for creating your own certificates / letsencrypt certificates or build optional tasks to create certificates.
Creating them with the Elastic CA could be an option but is not ecnouraged since users need to import the CA.crt file