Shouldn't be an issue to deliver two certificates an short lived one for TLS, an long lived one for the identity