Bug Fixes
- fix: resolve certificate/key mismatch in P12/JKS downloads - Fixed critical issue where private keys in P12/JKS downloads didn't match the certificate's public key (#1)
Root Cause
When issuing certificates, the KMS certify operation wasn't using the pre-created key pair, causing a mismatch between stored private keys and certificate public keys.
Impact
⚠️ Certificates issued before v1.3.1 are affected and should be revoked and re-issued.
Changes
- Added
UniqueIdentifierto certify request to reference existing public key - Added
PublicKeyLinkattribute as backup mechanism - Added test to verify certificate/private key modulus match
- Disabled key reuse for renewals (was broken for same reason)