- allow defining custom key/cert path - ensure key/cert directories - set key/cert permissions by metadata