The Canopy Server should force the HTTPS cert & private key files to have "400" permisions, the way SSH does.