Add a way for helpers to provide per-cert roots
Add a new output format which will allow helpers to supply root
certificates in addition to the issued certificate and whatever
intermediates (chain certificates) we also need. Continue to use the
PKCS#7 step to break apart signed-data blobs and handle decrypting
enveloped-data blobs. Migrate the internal postprocessing step to using
this same message format.