Comment by jeremyjh

3 years ago

The hard part is getting the root certificate in the trust store on every device in your organization.

Worse, it is often not the trust store on every device. It is often multiple trust stores on a device.

The OS might have one. Each browser might have its own. For a developer, each language they use might need separate configuration to get its libraries to use the certificate.