Old certs (including ca.crt/ca.key) need to be readable by 'nobody'. Change them to owner 'nobody' will do.
Another option is to remove all generated certs in the dir. Then they'll be automatically re-generated on demand with owner 'nobody'.
I did a fresh install of ab-solution and pixelserv. Every thing worked great. When I checked the ownership of the certs, ca.crt and ca.key belonged to the router, the others to nobody. I did change the ownership of ca.crt and ca.key to nobody. Everything is still working great. Is it a problem not to change the ownership.?