@lost_signal773 the problem with that is (at least) Windows will automatically connect to MS servers to download and install new Certs that 'they' consider OK - Honk Kong Post Office anyone?
I haven't dug into it much myself but I do have a passing interest to learn how to disable this 'feature'.