This fixes some problems with the cert plugin tests.

- It checks to see if a self-signed CA is available in ~/.ipa/alias. If not the tests are skipped
- Be a bit smarter about cleaning up by moving it to a separate test
- This relies on patch the service fix in 360. Some binary certs were being decoded as base64 resulting in an unparsable cert for the ASN.1 parser.

I also added a bit of documentation on how to set up the self-signed CA. It is a one-time thing.


