This avoids annoying problems like "too many" retries for certificate issuance, since we only ask for the secret once.