use uint32_t for certificate flags