Update certificates that expire on 2021, to prolong their validity, to make tests pass three years ahead.
Added tests to validate that certificates signed using SHA-1 are rejected by default, but accepted if SHA-1 is explicitly enabled.