right now the server keeps track of certs in a local folder. Both cfssl and vault have robust PKI APIs that the server can use instead.