Answers the AWS instance identity document certificate for a region.
RSA-2048 has no fallback and an unknown region is refused; RSA-1024 falls back to AWS's default certificate, as SPIRE does.
the AWS region
'rsa2048' or 'rsa1024'
the certificate as certificateFromDer() answers, or null
certificateFromDer()
Answers the AWS instance identity document certificate for a region.
RSA-2048 has no fallback and an unknown region is refused; RSA-1024 falls back to AWS's default certificate, as SPIRE does.