This updates the SSL/TLS validation to optionally ignore failures in OCSP/CRL list. If the revocation servers are offline or unavailable, the SSL requests will fail.
With the new option, `--ignore-revocation-failure`, it is now possible to ignore this class of errors and let the connections work anyway.
By default, this is off so we have the strictest possible security.
As part of this PR, there were a few places that did validation/override of certificates. With this change all calls route into the single `SslCertificateValidator` class so all certificate validations are done the same from ServerUtil, reporting modules and backends.