start implementing loading cert from filesystem, add validity times