fix(ext/node): fix TLS peer certificate multi-value fields, issuer chain, and EC curve names (#33782)
## Summary
- Support multi-value X.509 certificate fields (e.g. multiple OU
entries) by serializing as a string for single values and an array for
multiple, matching Node.js behavior
- Include CA certs in the server's TLS handshake chain (OpenSSL
auto-chain behavior) so `getPeerCertificate(true)` returns the full
issuer chain with self-signed root circular reference
- Fix EC curve names: use OpenSSL short names for `asn1Curve`
(`prime256v1` not OID) and NIST names for `nistCurve` (`P-256` not
`secp256r1`)
- Enable `test-tls-peer-certificate.js` and
`test-tls-peer-certificate-multi-keys.js` in node compat tests
## Details
### Multi-value certificate fields (`ext/node_crypto/x509.rs`)
`SubjectOrIssuer` fields were `Option<String>`, so when a certificate
had multiple values for the same key (e.g. two OU entries), only the
last was kept. Introduced a `StringOrArray` type that accumulates values
and serializes as a plain string (single value) or array (multiple
values), matching Node.js.
### Issuer certificate chain (`ext/node/ops/tls_wrap.rs`,
`ext/node/polyfills/_tls_wrap.js`)
`getPeerCertificate(true)` wasn't returning the issuer chain because:
1. The server only sent its leaf cert — rustls's `peer_certificates()`
returns only what the peer sent. Fixed by appending CA certs from the
`ca` option to the server's cert chain in `build_server_config`,
replicating OpenSSL's auto-chain behavior.
2. Self-signed root CAs didn't have `issuerCertificate` pointing to
themselves. Added the circular reference check in
`buildPeerLegacyCertificate`.
### EC curve names (`ext/node_crypto/x509.rs`)
`asn1Curve` was returning raw OIDs (e.g. `1.2.840.10045.3.1.7`) instead
of OpenSSL short names (`prime256v1`). `nistCurve` was returning
`secp256r1` instead of `P-256`. Fixed to match Node.js/OpenSSL naming
conventions.