ED25519 user/host CA keys generated; enableSSHCA on JWK provisioner;
24h root principal cert issued and used to ssh into sectestbed 5104
(passwordless, no static key). Host onboarding = 1 file + reload.
Rollout role queued in KNELIAC. Public CA key committed (private keys
never leave tsys-ca).
https://projects.knownelement.com/issues/385
http-01 validation, issuance, and chain all verified against the fleet
root via the prod endpoint; 5104 shut back down after the test.
https://projects.knownelement.com/issues/800