Trigger rekeying on key lifetime or use count
Add configuration options to specify key ages or use counts (where being
issued a certificate using the key pair counts as being used) after
which we'll want to initiate rekeying at the client during automatic
certificate replacement operations.