A new Certificate Authorities section in Reference Data provides full root CA lifecycle management: create, view, update, enable, and disable root CAs via PEM upload or paste. A unified wizard auto-detects the certificate type (root only, root with intermediate, or intermediate referencing an existing root) and visualises the trust chain as an interactive node graph. Administrators can edit a Root CA name or an Intermediate CA chain name directly, and the Intermediates tab supports View, Enable, and Disable with confirmation dialogs. The wizard resumes from the intermediates step on retry without re-creating the root CA, hierarchical mTLS trust constraints are enforced, and validation covers duplicate detection, invalid file formats, and required contact fields.