You had me until "and renew them".
Why would you need to renew a cert from anywhere?
The first part is straightforward: Have X systems retrieve/use a cert from a central location.
The X number of systems that can update that cert is the monkey wrench in the equation.
2 Likes