a realm id or PROCESS_SCOPE
the use case
publicKeyPem, subject, profile, extensions,
notBefore and notAfter
a promise of { ok: true, certificatePem, certificateDer, chainPem, issuerChainPem, ... }, the chain leaf first without the Root,
or { ok: false, errors }
Issues a certificate over a presented public key from a use case's Issuing CA, without recording it.
The caller owns what comes out (an X509-SVID, for one). The signature algorithm is the issuer's, the validity is clamped to the Issuing CA's, and the certificate carries no revocation pointers.