As done for InvalidCertificateHandler in #3299 would it be possible to do the same thing for PrivateKeyPassphraseHandler?
This would enable providing a password handler for the created context key allowing different contexts to be created with different certificate/key pairs without rewriting the global handle in SSLManager.