pub fn decode_issuer_key(ca: &CaConfig) -> Result<Vec<u8>, String>
Decode the issuer public-key bytes for a CA, falling back to a synthetic key.