# Diagnosis *2026-09-29.* ## What was ruled out **That something already carries the root and it is only misplaced.** It does not. The authority serves its root at a path beside its ACME directory, and the one thing that fetches it — the route proxy — puts it in a directory of its own and hands it to one program. Nothing has ever written into a machine's trust store. Measured on three converged machines: the anchors present are the predecessor's authority and a developer tool's local root, and on the machines where the predecessor's was deliberately removed, every internal name fails verification. **That the private network could carry it, the way it carries the registry's trust.** That is what the report proposed, and it was rejected on consideration rather than on difficulty ([ADR 0147](../../02-DECISIONS/0147-a-module-anchors-the-meshs-authority.md), option 1): being on the network is what makes the registry *reachable* and is therefore the right trigger there, while trusting an authority is a separate fact from being able to reach it. The anchor's directory and the command that refreshes the extracted bundles are also one operating system's difference, which is the host's half of the mesh and not the controller's. **That it needs a new host resource type.** It does not, today. A file and a service say the whole of it, which the packet filter already proves. The primitive becomes the right answer when a second operating system is in play, and not before. ## Where it belongs A module in the catalogue: it requires `internal-acme-ca`, fetches the root over the mesh's own network, installs it as a trust anchor, refreshes the machine's bundles, and — because being unassigned stops its unit, and stopping the unit is what undoes it — takes both away again. The owner is therefore `mesh-catalog`, module `ca-trust`, and nothing in the control plane.