1. Generate root CA 2. Generate wildcard CSR 3. Sign wildcard CSR with root CA 4. Install root CA system-wide