* make handling the default certificate more sensible (still needs work!)
* better document CertificateStore
* split off default certificate functionality into separate class CertificateStoreWithDefault
* rework CertificateStore testing infrastructure (introduce common base class)
|