Please check your digest provider. You are generating a certificate for pkcs#7mbedtls but the mbedtls_pk_parse_public_keyfile error point to mbedtlsRSA being active at runtime. You can force the provider with the --digest-provider option.