Correct path for ca cert, and add crl checking (this may not work, but