pass back an heim_error from hx509_cert_init