the TLS listener
its name, for the log
optional; for a listener that presents a certificate
of its own rather than this module's (a realm's listener, #99), answers
{ key, cert } each time the truststore is applied
optional { kind, realm } naming the listener's policy
(policyFor(), #423); omitted, the main port's
true when it was registered; false (logged) when server is not a
TLS server
Registers a TLS listener created elsewhere so that the client truststore, and every change to it, applies to it too.