god. ssl certs are a pain in the ass
bouncycastle to the rescue, as usual