Convenience CA for SUBFROST-issued certificates. The primary trust model is end-to-end self-signed certs pinned on-chain in the subdns alkane — the gateway passes TLS through and clients verify the leaf against the on-chain pin.