implement certificate validation (including CN verification)