Emit each loaded keybox's certificate-chain serials (lowercase hex) at parse time. A revoked or leaked keybox is then visible from logcat alone, since Google's CRL and Duck Detector's "mass abuse" check both match by certificate serial. Diagnostic aid for the revoked-keybox danger in #28; the actual fix is rotating to a non-revoked keybox.