Restarting the Encaya service seems to cause some intermittent issues in CryptoAPI because the TLD CA gets regenerated. This tends to resolve itself once the CryptoAPI cache gets flushed, but this can take a while and is quite annoying. Persisting the TLD CA to disk like we do for the root CA should be a harmless and easy way to handle this.