ReadonlycertificateReadonlyprivateThe raw private key. Kept for compatibility — new code should prefer
ICertificateKeyPairProvider2.getKeyOperations (via
getKeyOperationsFromProvider), which works whether the key is local
or HSM/KMS-held; an opaque provider implements this method by
throwing PrivateKeyUnavailableError.
Optionalinvalidate
Extends ICertificateKeyPairProvider with diagnostic file-location properties so that consumers can report where certificates are stored (real path or
"<in-memory>").Does not alter the public
ICertificateKeyPairProviderinterface — zero breaking change toServerSecureChannelParent,ClientSecureChannelParent, or any external implementation.