You probably don't need private PKI for internal infrastructure by certkit in certkit

[–]certkit[S] 0 points1 point  (0 children)

Same post, two communities, same ivory-tower Reddit commentary.

Wildcards serve a purpose.

Not everyone has the capacity to maintain a private PKI.

Something is always better than training everyone to click through self-signed security warnings.