CACreateCert: never default to less than sha-256 if SHA-2 available