You normally do not need to configure the replica with the source server’s certificate and private key. The source keeps its own server-cert.pem and server-key.pem; the replica only needs the trusted CA unless mutual certificate authentication is required.