Certifies a realm's signer groups: one hybrid certificate per classical and ML-DSA pair, and a plain one for the SLH-DSA key.
A slot already over the same keys from the current Issuing CA is left alone.
the realm
the signer group members
a promise of { ok, certified, unchanged, failed }
{ ok, certified, unchanged, failed }
Certifies a realm's signer groups: one hybrid certificate per classical and ML-DSA pair, and a plain one for the SLH-DSA key.
A slot already over the same keys from the current Issuing CA is left alone.