Out of band (ssh, scp etc) or via curl/wget http to a non-fabric public CA (e.g. letsencrypt) identified https endpoint.

If keys are generated by the CA then what is the best way to distribute these keys?

