(PUP-1409) add authorityKeyIdentifier to client certificates
As discussed in the ticket this will add the authorityKeyIdentifier that
is not required, but recommended to add to certs signed by a CA
conforming to RFC 5280. This extension takes the subjectKeyIdentifier of
the CA certificate and adds it as keyid to authorityKeyIdentifier. This
PR also adds a test to make sure the extension is correctly added to the
resulting certificate.