Registers handle if not already present.
Must not race with reEncryptAll; call during single-threaded startup.