Internal CA Trust Is an Operator Onboarding Problem
A valid internal TLS certificate is still unusable on a new operator device until its trust root is installed correctly.
A valid internal TLS certificate is still unusable on a new operator device until its trust root is installed correctly.
Publishing a certificate means every directory in its path must support the intended reader, even if neighboring secrets remain private.
The server needs its TLS private key to operate, while the CA private key is more powerful and should remain off-host.