This is a sensible solution but one that won't work for me personally. I don't have the physical room in my little apartment to have two systems set...
Actually sha1WithRSA is valid algorithm which, so it can be considered kernel bug to not accept it. But certificates themselves look rather strange
...