properties: allow choosing certificate from a PKCS#11 token

Apparently, openconnect can handle certificates from PKCS#11 tokens.
Drop the NMA_CERT_CHOOSER_FLAG_PEM flags from NmaCertChoosers.
2 jobs for lr/pkcs11 in 16 minutes and 56 seconds (queued for 1 minute)
latest