- install the cert of the CA that signed the boot server cert on the