883322cadf
Chain members are now installed before the leaf, so the certificate is chainable the moment it appears in the store rather than momentarily orphaned. After -InstallChain the chain is validated against the machine's own stores. An incomplete result is reported as a warning naming the certificate whose issuer is missing, which is the exact condition Windows surfaces as "The issuer of this certificate could not be found" - previously that was only discoverable in certmgr after the fact. Chain routing is unchanged and already handles arbitrary depth: a self-signed certificate is a root and goes to the trusted-root store, anything with an issuer above it is a subordinate CA and goes to the intermediate store. Only the leaf honours -StoreName (default My). This is now stated in the docs, because the split was not obvious. The installed certificate's Windows friendly name defaults to the common name in upper case, which is what operators look for in certmgr. -FriendlyName overrides it and moves from the ByCa parameter set to all of them; the CA path still forwards the same value to Infisical as the issued certificate's friendlyName. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>