Would like to update the generation of the SKI to use a more modern algorithm. Seems prudent in the face of SHA-1 problems. Already rolled out by [letsencrypt](https://community.letsencrypt.org/t/enabling-sha256-subject-key-identifiers-for-end-entity-certificates/211453).