The raw private key. Kept for compatibility — new code should prefer
ICertificateKeyPairProvider2.getKeyOperations (via
getKeyOperationsFromProvider), which works whether the key is local
or HSM/KMS-held; an opaque provider implements this method by
throwing PrivateKeyUnavailableError.
Extends ICertificateKeyPairProvider with the key as an opaque sign/decrypt object, so consumers can use the private key without ever holding its material — the seam HSM/KMS-held keys plug into.
Same additive pattern as ICertificateKeyPairProviderWithLocation: the base interface is untouched, existing implementations stay valid, and getKeyOperationsFromProvider bridges the gap by wrapping
getPrivateKey()locally when a provider does not implement this.