@Mistiz you shouldn’t need any certificates for MM to external connections, as the source server is required to provide the cert that covers its connections…
MM does not provide a cert, as we don’t use http,
assuming we are on a close private network in our homes.
certs are a pita(pain in the a) in general …
for access INTO my system , I no longer use an open port, and don’t have to provide certs for every source, or router module(gateway)
I use cloudflare zero trust tunnel. they provide the cert, and maintain it.
their endpoint connector runs on your network and can http connect to services at that level.