A certificate loaded into a controller is stored within an encrypted key store on an encrypted partition. It is also possible to use a passphrase for storing/uploading the certificate/private key. Certificates can only be managed through the web UI when enabled, or via the SCP driver.