Comment Hard for users to trust a private CA (Score 1) 21
Other than that new versions of mainstream operating systems and web browsers make it harder for the owner of a device to trust the root certificate of a particular private CA. I seem to remember, for example, that iOS and Android put a scary warning on the lock screen if one or more user-trusted root certificates is installed, and Android application developers have to opt into user-trusted root certificates through a "Network Security Config".