When not waiting for a certificate we cannot rely on Ansible to update user and group because the file won't exist.
Instead we should create a script that will run chown and pass this script to certmonger execute just after the certificate is issued/renewed.