Is it possible to fail a request if the fallback cert is to be served e.g. return 404 as opposed to serving the self-signed cert?