Some upstream keybox sources inject HTML comments inside PEM certificate blocks. BouncyCastle's PEMParser chokes on these non-base64 lines, silently failing to load the keybox. Filter lines starting with <!-- in trimLines() before the content reaches the PEM parser.