Don't fail OCSP validations for intermediate certs if the root certs are signed by sha1 and sha1 is disabled.