Add certificate when creating a k8s load balancer

I am using Rancher 1.6.12 to create my k8s stack on aws.

What is the proper way of adding a certificate when creating a LoadBalancer service (which in our rancher-k8s case will translate to the launch of a HAProxy container) ?