Anti-MITM re-verification: before sealing to a public encryption key served by the directory,
the sealer re-derives the binding from the args (never trusts a passed-in string) and checks the
recipient's Ed25519 signature over it. If the directory swapped the lock, this fails.
Mirrors verify_enc_key_binding in sealed_field.rs.
Anti-MITM re-verification: before sealing to a public encryption key served by the directory, the sealer re-derives the binding from the args (never trusts a passed-in string) and checks the recipient's Ed25519 signature over it. If the directory swapped the lock, this fails. Mirrors
verify_enc_key_bindingin sealed_field.rs.