V1 certificates that aren't self signed can't be accepted as CAs.