The stamp should always generate a server public/private keypair on first boot if one is not present in flash, and then have a mechanism for the user to trigger generation of a new server identity (to replace the previous one) if needed.
Afterwards, provide a configuration flag (see issue #23) so that the user can re-generate those keys on demand.