ku_reject
if (!ku_reject(reqctx->received_cert,
if (!ku_reject(x, X509v3_KU_DIGITAL_SIGNATURE))
if (!ku_reject(x, X509v3_KU_KEY_ENCIPHERMENT))