New subcommand to lookup by label using an ORCA engine
Not quite sure how it should be called, but it should read in all certs, load the trust root, then find all certs matching the label authenticated by the ORCA engine.
Blocked by: sequoia#720 (moved)