a realm id (a process use case uses the process branch)
the use case
slot, dnsNames, ipAddresses, keyAlg, commonName,
label and days
a promise of { ok: true, issued }, issued carrying the
certificate, the private key and the anchor, or { ok: false, errors }
Generates a TLS server key pair for a listener this service does not run (a remote XACML PEP's), certifies it and hands the private key back once.
The certificate is recorded under the slot; the private key is not kept. A certificate with no subjectAltName is refused.