OptionalautomaticallyOptionaldisableOptionalkeyUse a private key this manager can never read: an opaque
IKeyOperations provider (HSM, KMS, TPM, OS keystore). Unlike
privateKeyProvider — which sources raw key material — the key never
enters the process: getPrivateKey() throws
PrivateKeyUnavailableError and every use goes through
getKeyOperations(). Mutually exclusive with privateKeyProvider
and privateKeyPassphrase. See node-opcua-pki's
private-key-protection guide for the full contract.
OptionalkeyOptionalnameA label for this store. It does not change where the store lives:
the folder is rootFolder alone. Callers that want one store per name
build the path themselves, as getDefaultCertificateManager does
with rootFolder: path.join(config, name).
OptionalprivateEncrypt the private key at rest with this passphrase (opt-in, default off — a plaintext key is written, exactly as before). When set:
initialize() closed with PrivateKeyPassphraseRequiredError.A function is called at most once per OPCUACertificateManager
instance (the decrypted key is cached in memory for the instance's
lifetime, see OPCUACertificateManager.getPrivateKey). Never
logged.
The in-process default managers returned by
getDefaultCertificateManager (memoized by name, e.g. "PKI" /
"UserPKI") are always passphrase-less — construct your own
OPCUACertificateManager and pass it as serverCertificateManager /
clientCertificateManager to use passphrase protection.
OptionalprivateSource the private key from somewhere other than
own/private/private_key.pem (an HSM, a KMS, ...). When set, it
overrides disk entirely for every operation that needs the private
key — the on-disk file is not read, and privateKeyPassphrase is
ignored.
OptionalrootThe folder that is the PKI store: own/, trusted/, issuers/ and
rejected/ are created directly under it. name is not appended.
Two managers given the same rootFolder share one store and one
private key, whatever their name. Give every application, and every
side of an application (server side, client side), a folder of its own.
When
true, file-system watchers (chokidar) on the PKI folders are disabled. The initial scan still populates the in-memory indexes but live change detection is off.Useful in test / CI pipelines where many servers start in parallel and the accumulated
fs.watchhandles exhaust the libuv thread-pool.