cert_flags is unsigned