[CreateCertificate] now uses truncated SHA-256 to populate the SubjectKeyId if it is missing. The GODEBUG setting x509sha256skid=0 reverts to SHA-1.
SubjectKeyId
x509sha256skid=0