* Provide base64 keys in addition to hex encoded. Accept these at unseal/rekey time. Also fix a bug where backup would not be honored when doing a rekey with no operation currently ongoing.
(very unlikely) potential timing attack between init-ing and fetching status. Fixes #1054