security_idWriting one OCF `security_id` into both `Certificate.id` and `Certificate.securityId` (and the RSA equivalents) asserts that the two slots hold the same value. The bundle describes them differently — `id` is "the identifier of the certificate", while `securityId` is "the UUID of the certificate. Use this to cross-reference with the List Transactions API" — so they may be distinct identifier spaces, with `securityId` server-assigned rather than client-supplied. Neither is marked `readOnly`, which is why both are currently mapped; this pattern was added across the issuance, exercise, cancellation, and repurchase mappings when June 22 made `id` required, so a single answer settles all of them.