Is it possible to restrict the exposure of Keycloak’s TLS certificate revocation endpoints and other potentially sensitive API endpoints to prevent public access? If so, what are the recommended configurations or best practices to secure these endpoints without impacting system functionality?