enforce_sane_certificate_state(): Also deal with certificates without key