How to add a custom PKI the right way?

Hello !

At home I’ host multiple services for my personal needs. To deploy them the right way, I’ve made a custom PKI to generate TLS certificates for all of them, and then added my root CA to all my devices with success (android, multiple linux, sip phones and a steamdeck). The only device with which I have issues is my SFOS smartphone.

It’s not that I’m unable to add the root CA to the SFOS CA store, this step is quite similar to other linux, I can see it from the Settings > Certificats > TLS Certificats and I can wget an https content from the CLI. It’s more that I don’t understand what should I do to exploit this certificats with sailjail apps ?

One of my services is a ZNC (a IRC bouncer). When I attempt to connect Communi to it, I have a not very explicit error. When I made the same attempt with Sailtrix to my synpase, in the terminal I got TLS errors. Does anyone have an idea of how to solve this ?

I’m absolutely not sure, but this documentation may help you: Email | Sailfish OS Documentation