the person's username
the key pair from pki.js: private key, certificate, chain,
JWKS, kid or thumbprint, notAfter, source
purpose (jwt by default), issuer to declare, and
initiatingEntity and via for the event
{ ok, written, errors }, with errorCode on a refusal
Writes an issued or uploaded key pair onto a person's entry, every attribute or a failure naming which one.
The private key is sealed and written first; a key pair that fails to seal or write is lost, since this service keeps no copy. A CAEP credential-change event follows a successful write.