A Raspberry Pi 3 can work well as a private lab OTA repository and internal certificate service, but the first architectural decision is crucial: do not treat the online Raspberry Pi as your root CA or primary firmware-signing authority. Separate certificate issuance, firmware signing, artifact storage, and deployment management from the beginning.
- First decide what you mean by “CA server”
You potentially need three different trust functions:
TLS certificates