pub fn load_seal_materials(
ca_config: &CaConfig,
) -> Result<(SealKey, Vec<u8>), String>Expand description
Load the seal key and certificate for CMS bundle sealing.
Falls back to the OCSP signing key if no seal_key is configured and the
signing key is ECDSA P-256. For ML-DSA signing keys (which are not P-256),
falls back to an ephemeral demo seal key with a warning.