Factor out enforce_sane_certificate_state()