docs / Operating
Private PKI
The PKI page issues certificates directly from your Private CA — useful when you need an identity a public CA won't provide (internal hostnames, service mesh, client certificates).
It supports both classic keys and Post-Quantum (ML-DSA). Certs from a Private CA are trusted only by systems inside your organization that have installed the root CA — they are not a public trust anchor.