- Don't check mtime of certificates, and make cerificate update explicit. - Add ability to specify CA for accepting client certificates.