Personally, I think the current description of what certificates should be installed where is a little bit confusing.
Perhaps we should add a page describing a high level overview of what is stored where and whom is authenticated using those certificates to help clear some confusion.
@Lut99 Since you designed this system could you give me a rough sketch/outline, and I will try to make it ready for actual usage.