@jkeyser As far as I understand, The certs are held on the processor and the processing in done on the processor not the modem.
From the various services I tested (AWS/Azure/Private server and others I cant remember name off without checking my book) all certs are save device side and server side and never transmitted during communications.