* Proper encapsulation * known_hosts2 backend extended (storing PEM) * New backend storing each host certificate in a file