vouchesForPastOperations static method
Whether status still vouches for what the key already did — verifying a
stored envelope or chain link that names it.
active and retired, because retirement withdraws the future and keeps
the past. Not known.contains(status), which would be the same answer
today and the wrong one the moment a value like revoked is added: a
token joins known by being understood, not by being trusted, and the
first token anyone adds here is likely to be one that must fail this.
Implementation
static bool vouchesForPastOperations(KeyEntryStatus status) =>
status == active || status == retired;