pub fn revoked_serials_for_scope(
ca_config: &CaConfig,
persistent_sources: &PersistentSources,
) -> Result<BTreeSet<SerialBytes>, String>Expand description
Snapshot a CA scope and return the set of currently-revoked serials, without signing or writing anything. Used by the signer loop’s urgent-revocation detector to diff against the previously-known revoked set between scheduled passes. Reuses the shared persistent source so a syncrepl cookie is not reset.