A bounded X.509 certificate retaining both its exact DER and decoded OTP form.
@type t() :: %SSL.PKIX.Certificate{decoded: term(), der: binary()}