Decides one certificate's status from CRLs already in hand, never fetching.
The same route a fetched list takes; used by the x509-limbo and PKITS tests. Never rejects.
{ certificate, issuer, others, crls }: the certificate, its issuer, other certificates that may sign an indirect CRL, and the CRLs as DER or PEM
{ certificate, issuer, others, crls }
{ status, why }, the status good, revoked or unknown
{ status, why }
good
revoked
unknown
Decides one certificate's status from CRLs already in hand, never fetching.
The same route a fetched list takes; used by the x509-limbo and PKITS tests. Never rejects.