Your Own Certificate Authority: step-ca In A Container
Running Smallstep’s step-ca 0.30.2 in a Podman or Docker container as the certificate authority for everything inside the house, all of it tested. Why a private CA beats self-signed certificates and public ones for internal names, starting it with ACME and SSH switched on, the two passwords the image generates and where each one goes, trusting the root on every device, internal HTTPS for Caddy or anything else that speaks ACME, and step ca renew for services that do not. Client certificates and SSH each have their own post.