The Certificate Token lets you enroll an x509 ceritificate by the given CA.
The server will create the private RSA key and return it with the certificate in an encrypted PKCS#12 container.