pub const CERT_TRUST_IS_KEY_ROLLOVER: u32 = 128u32;