pub fn create_cms_seal(
manifest_bytes: &[u8],
seal_key: &SealKey,
seal_cert_der: &[u8],
) -> Result<Vec<u8>>Expand description
Create a detached CMS SignedData seal over the manifest bytes.
Accepts any SealKey variant (ECDSA-P256 or ML-DSA). ECDSA uses
prehash signing; ML-DSA signs the raw signed attributes DER.