Optional
memberVerifier for member RSA-OAEP certificates.
This is only used if a Name would be passed to KekHandle.grant function. If unspecified, KekHandle.grant does not accept Name.
Decrypter for own KDK.
Encrypter for own KDK.
Optional
ownVerifier for own KDK.
This is only needed if Options.dataStore cannot be trusted (e.g. it's a network based repo). Otherwise, no verification is needed.
Signer for KEK, KDK, and KDK SafeBag.
Set of keys used by AccessManager.