docs / Operating

Private PKI

The PKI page issues certificates directly from your Private CA — useful when you need an identity a public CA won't provide (internal hostnames, service mesh, client certificates).

It supports both classic keys and Post-Quantum (ML-DSA). Certs from a Private CA are trusted only by systems inside your organization that have installed the root CA — they are not a public trust anchor.