We should watch SSL certificates on disk and reload them (and recreate `SSL_CTX`) when they change. It's unclear whether this is the perfect solution (vs LDS with encrypted private keys). Needed by Istio. cc @kyessenov @louiscryan