the realm; the ambient realm when absent
the holder's username or application identifier
the certificate's serial number in hex
one of REVOCATION_REASONS; cessationOfOperation
otherwise
'person' or 'application'; a person when absent
the revocation's outcome with the certificate and reason, or
{ ok: false, errors } when the holder holds no such serial
Revokes one of the holder's own certificates, found by serial among that holder's certificates only.
A person's revocation raises CAEP (and, for
keyCompromise, RISC) events.