i guess doing it as a root cert lets me play around with X.509 in an environment where hecking up doesn't matter so... yeah i'll do that
@catoutofbed fun fact: snmp and ldap are siblings of TLS