Generate a self-signed TLS certificate + private key (PEM) on this host.
<data>/certs). The private key never leaves the server — this page shows
only the file paths and the SHA-256 fingerprint. Point your TLS settings at the generated
.crt / .key paths. Requires the manage_certificates permission.