Finds the public key a SET was signed with among the ambient realm's own
signing keys, by kid first and by algorithm only where there is no kid.
It fetches nothing.
Parameters
header: any
the SET's protected header
Returns {key:any;pq:boolean}
{ key, pq }, or null when this service holds no such key
Finds the public key a SET was signed with among the ambient realm's own signing keys, by
kidfirst and by algorithm only where there is nokid. It fetches nothing.