pub fn rotation_due(entry: &Value) -> Option<String>Expand description
When rotation is next due, anchored on the last rotation or, failing that, on creation.
A 90-day key that has never been rotated is due 90 days after it was issued, not never. An entry with neither anchor gets no event: putting a deadline in someone’s calendar that no evidence supports is worse than leaving it out.