Adds Application certificate path to profile
Prior to this patch, the API Profile type had no way of exposing the
path to an application certificate. While this could be constructed
manually using the `keypaths` package, this was fragile and easy to miss
should the profile layout ever change.
This patch adds `GetAppCertPath()` to the API profile, providing a
centralised and integrated method for finding application
certificates.