Add config options for:
- Setting the validity duration of generated certs
- Lookahead time for the regenerate-when-expiry-is-near trigger
We should put off doing this until more frequent cert rotations are safe WRT availability. The work for doing so is listed in the "Allow Setting Cert Validity Duration" milestone.