Key capabilities
- Parse certificate, PKCS#10 CSR, SPKI, PKCS#8, PKCS#1, and SEC1 structures
- Show SAN, key usage, constraints, identifiers, policies, AIA, and CRL indicators
- Flag validity windows, weak signatures, small RSA keys, and hostname mismatch
- Compare normalized public components without exporting private-key material
