I noticed 3 cases on oasis-itb and one on oasis in the last 2 weeks where the masterkeycard appeared to be unavailable at the beginning of resign_osg_whitelist so no signatures were tried. Have it check cvmfs_server masterkeycard -k twice
Do the same in recover_oasis_rollback and oasis_status_stamp. Everywhere else gets repeated by cron anyway so it doesn't matter.
This is now in oasis-goc-zero-2.1.29-1.osg34