Public certificates and private keys are stored on the NSX Managers. When a load balancer or a VPN service is created that requires a private key, NSX Manager sends a copy of the private key to the Edge node where the load balancer or VPN service is running.