The task importing the client certificate passed `certificate_authority_client_tls_crt_content` to `dest`, so the PEM payload itself was interpreted as a directory path. The certificate was written to a bogus location derived from its own content instead of the configured client directory. Use `certificate_authority_client_path` as destination, consistent with the private key import above. Co-authored-by: Copilot <copilot@github.com>