security/vuxml: Correct the step-cli vuln
It's not the client, it's only the server: step-certificates