path to the certificate (chain) PEM file
path to the private key PEM file
Optionalpassphrase: string | Buffer<ArrayBufferLike>
optional passphrase to decrypt privateKeyFile if it is
an encrypted PKCS#8 key. Omit for a plaintext key. If the key is encrypted
and no (or the wrong) passphrase is given, getPrivateKey() throws
PrivateKeyPassphraseRequiredError (fails closed).
Clears cached secrets so the GC can reclaim sensitive material. After calling dispose the holder will re-read from disk on next access.
The key as an opaque sign/decrypt object — see localKeyOperationsOfProvider.
The raw private key. Kept for compatibility — new code should prefer
ICertificateKeyPairProvider2.getKeyOperations (via
getKeyOperationsFromProvider), which works whether the key is local
or HSM/KMS-held; an opaque provider implements this method by
throwing PrivateKeyUnavailableError.
Alias for dispose.
Implements ICertificateChainProvider.invalidate().
Provides a certificate chain and private key to an OPC UA endpoint.
Implementations may read from memory, disk, or any other source. See also DiskCertificateKeyPairProvider which implements this interface for disk-based access with lazy caching.