[arch-general] Rethinking our CA certificate setup