Something I forgot to mention, I'm also going investigate the use of a HSM.
Maybe this could make things easier as apparently peers and orderers can connect to the HSM. If it enabled the retrieval of their certificate and private key, this would be great.