Real path of the private key file (needed by push-management, even though the key itself is held in memory).
The key as an opaque sign/decrypt object — see localKeyOperationsOfProvider.
The raw private key. Kept for compatibility — new code should prefer
ICertificateKeyPairProvider2.getKeyOperations (via
getKeyOperationsFromProvider), which works whether the key is local
or HSM/KMS-held; an opaque provider implements this method by
throwing PrivateKeyUnavailableError.
Re-reads the certificate chain from disk on next access. The in-memory private key is untouched — construct a new provider to rotate the key (see class doc).
Provides a certificate chain and private key to an OPC UA endpoint.
Implementations may read from memory, disk, or any other source. See also DiskCertificateKeyPairProvider which implements this interface for disk-based access with lazy caching.