Thank you all for answering.
I changed config.tcl setting CADir to /usr/share/ssl and CAFile to /usr/share/ssl/cert.pem and now nsd starts without any error.
I also copied security-procs.tcl from cvs 5.1 as per Jade's suggestion. I'm using nsopenssl 3 beta 17, but my Mozilla 1.0.1 hangs forever as soon as I leave https for http.