URL: https://github.com/freeipa/freeipa/pull/490
Title: #490: [WIP] certdb: use certutil and match_hostname for cert verification

tiran commented:
The hostname must be ASCII text. Something like ```hostname.encode('ascii')``` 
should catch non-ASCII text and Python 3 bytes.

See the full comment at 
