Fix new-certificate semantic: CertsPath fallback + --force rotation + clearer description
Summary
Three fixes bundled (all surfaced via Linux D4h E2E iterations):
-
CertsPath fallback:
create-instance + new-certificateflow no longer crashes withArgumentException: path empty. Falls back toInstanceSelector.ResolveCertsPathwhen settings.CertsPath is empty. -
--forceflag for actual rotation: deletes existing cert + lets LoadOrCreateCertificate regenerate. Default behavior unchanged (load-or-create). Subscription-id preserved across rotation. - Description text clarified: "Ensure a Tentacle certificate exists (or rotate it with --force)".
Plus a clear post-rotation message reminding operators they MUST register --force (PR #265) to push the new thumbprint to the server's trust list.
Why this matters
Operators reading show-config's "expires in N days
Test plan
-
dotnet buildgreen -
CI: existing D4h E2E pin still passes (default load-or-create unchanged) -
Future: add D4h2 asserting --force actually rotates (separate follow-up PR)