test-ca.crt — self-signed test CA (the trust anchor for tests) test-ca.key — test CA private key (DO NOT use in prod) valid.{key,crt} — leaf with correct CN/SAN, valid 30d wrong-cn.{key,crt} — leaf with correct format but wrong source_id in CN expired.{key,crt} — leaf expired yesterday (negative days) no-san.{key,crt} — leaf with correct CN but no SAN untrusted.{key,crt} — leaf signed by an UNTRUSTED CA (simulates attacker) untrusted-ca.{key,crt} — the attacker's CA Production uses scripts/cert-manager/ca-init.sh to generate the real PKI. This dir is .gitignored.