findPkiTrustAnchorsToAdd

internal fun findPkiTrustAnchorsToAdd(installedAnchors: List<CertificateChain>, pemBundle: String): List<CertificateChain>

Returns the certificates from pemBundle that are not in installedAnchors.

Core Crypto 10.4 rejects duplicate additions, but its Kotlin bindings do not expose a typed error for that case. Comparing fingerprints before calling Core Crypto keeps retries safe. Installed trust anchors are never removed.

Core Crypto identifies each trust anchor by the SHA-256 fingerprint of the certificate's DER-encoded SubjectPublicKeyInfo. This function parses and fingerprints the complete bundle before returning, so malformed input fails before the caller adds any certificate.