Put the certs into a temp dir rather than a protected system dir (/var/run) which only root can access.
These should be called only by a script (or a user) who knows that the binaries are built and correct. Normal users should just have the versions in ../ which should just always do a build.