a realm id or PROCESS_SCOPE
the use case
the slot, publicKeyPem, and optionally alg, kid,
label, commonName, keyUsage, extensions, days and the pinned
material
a promise of { ok: true, certificate, record } or
{ ok: false, errors }
Certifies one key pair from a use case's Issuing CA and records the certificate in the slot the spec names.
The caller keeps the key. A branch that no longer chains to the Root is repaired first (unless
spec.repairBranchis false). Answers rather than throws when there is no Issuing CA.