* initial openssh certificate support
* use the certificate to construct the public key instead of storing a map in memory
* move certificate check into its own function and neaten up a few things
* final requested changes
Co-authored-by: Max Goedjen <max.goedjen@gmail.com>