OPC Data Source with sign and encryption

When setting up an OPC data source, if Sign & Encrypt is selected for the Security Mode, Tulip is looking for a Private Key and Certificate file. I assume the certificate file can be created from the .der file from the OPC server (KepServer in my case).

Where does the Private Key come from?
Is this something that comes from the OPC server also?
How do I create the Private Key file?

I’m looking into getting Sign&Encrypt setup as well but cant seem to find any info related to it in Kepware help files.

Maybe @royshilkrot /@Het/or any other users who’s set this up can point us in the right direction?