There is no key file: the key lives inside the ops provider.
The key facts, prefetched at construction — synchronous by design.
The raw private key. Kept for compatibility — new code should prefer
ICertificateKeyPairProvider2.getKeyOperations (via
getKeyOperationsFromProvider), which works whether the key is local
or HSM/KMS-held; an opaque provider implements this method by
throwing PrivateKeyUnavailableError.
The key's public half (SPKI DER), when the ops object could produce it.
Re-reads the certificate chain from disk on next access; the ops object and metadata are untouched.
Provides a certificate chain and private key to an OPC UA endpoint.
Implementations may read from memory, disk, or any other source. See also DiskCertificateKeyPairProvider which implements this interface for disk-based access with lazy caching.