A2AAgentRegistration has no caCertSecretRef, so an upstream agent serving TLS with a private CA can't be registered — MCPServerRegistration supports this (labeled CA secret, PEM validation, size cap, http->https scheme upgrade). Port the same field and machinery once there's a demand signal ; deliberately excluded from the steel thread (#3) as breadth. The MCP implementation is directly reusable, including validateCACertPEM.
A2AAgentRegistration has no caCertSecretRef, so an upstream agent serving TLS with a private CA can't be registered — MCPServerRegistration supports this (labeled CA secret, PEM validation, size cap, http->https scheme upgrade). Port the same field and machinery once there's a demand signal ; deliberately excluded from the steel thread (#3) as breadth. The MCP implementation is directly reusable, including validateCACertPEM.