Our own certificate authority issues the certificates our internal sites and applications use. The root certificate is public: copying it grants nothing, which is why it can be published. With it installed, our internal sites stop raising warnings.

Before installing any root certificate, check its fingerprint with a trusted person — not against the page that served the file, which cannot vouch for itself. Ours carries no name constraints, which is ordinary for a private authority and worth knowing: while it is installed, a machine will accept any certificate we sign, for any name.
SHA-256  10:10:C4:D0:0D:6E:1D:A8:FE:A9:A8:A3:C2:58:D0:D5:A6:C6:E1:41:93:62:A9:4F:59:63:A5:8F:7E:3A:9F:D1

Download the root certificate

How this fits into sign-in and access is under Identity & access.