load certificate and csr on demand; separate certificate checks into separate class; add check private key matches certificate; more checks work