Technically, a more correct name for an SSL certificate is a "PKI (public key infrastructure) certificate using the TLS protocol"
On a Satellite,
/etc/pki/katello/certscontains all of the Katello's certs, including server and CA/etc/rhsm/ca/katello-server-ca.pemcan be ignored - this is on the system if it is a client of another katello #KatelloInception
On a Katello client,
/etc/rhsm/ca/katello-default-ca.pemcontains the pki certificate from Katello downloaded with
rpm -Uvh http://katello.example.com/pub/katello-ca-consumer-latest.noarch.rpm
/etc/pki/consumercontains the identity certs of the Katello client, signed by the Katello CA/etc/pki/entitlementscontains entitlement certificatessubscription-manager cleanwill remove local data including certs in /etc/pki/consumer