CA used to sign the new certificate -- accepts '[file:]fname' or 'env:varname'.
string
"${cfg.dataDir}/ca.pem"