1) Give it a version number and publish it in vdt-version
2) Store the configuration file in vdt-app-data. We want it preserved
across updates so that we don't have to tell people to back it up.
3) Add an "exclude_ca" option. It will work as follows:
In the vdt-update-certs.conf file, a line can be added similar to
"exclude_ca=12345678". This will remove all files in the certificates
directory that match the glob "12345678.*". This prevents admins from
needing to specify exclude statements for each of the 5-6 files that
come with a CA.