-----BEGIN CERTIFICATE----- PLACEHOLDER — replace this file with the real AD CS root certificate (PEM-encoded, base64, "-----BEGIN CERTIFICATE-----" ... "-----END CERTIFICATE-----"). To obtain: export the "Root CA" certificate from AD CS ( certlm.msc → Trusted Root Certification Authorities → Certificates → right-click → All Tasks → Export → Base-64 encoded X.509 (.CER) ). This file is NOT secret — it's a public trust anchor. Committing it to the repo is fine. -----END CERTIFICATE-----