newPublicKey
The key that was refused, kept so the mismatch can be shown as more than a warning.
Null whenever keyMatch is true. Rows that recorded a mismatch the old way, as ERROR_BYTE_STRING in publicKey, have no rejected key to report and stay null.