{ config, lib, pkgs, ... }: { security.pki.certificateFiles = with pkgs; lib.lists.optionals config.sas.build.private [ "${sas-cacert}/etc/ssl/certs/ca-bundle.crt" ]; }