Initial support for certificate purpose checking: this will