implement optional SSL certificate validation (including CN host check)