therefore we have to duplicate it in store: * encrypted for to serve for clients (encryptedExpirationDate) * unencrypted for server to check if it's exceeded (serverExpirationDate) serverExpirationDate should never be send to client