      Fix X.509 keysize check with multiple CAs · fa67ebae
      Assume we have two trusted CAs with the same name, the first uses ECDSA 256
      bits, the second RSA 2048; cert is signed by the second. If we do the keysize
      check before we checked the key types match, we'll raise the badkey flags when
      checking the EC-256 CA and it will remain up even when we finally find the
      correct CA. So, move the check for the key size after signature verification,
      which implicitly checks the key type.
      Tune up Windows snprintf() support · f659d2cd
      When we build with Visual Studio in debug mode, the invalid parameter handler
      aborts the application (and offers to debug it) when n is 0. We want to
      just return -1 instead (as calls with n == 0 are expected and happen in our
