As mentioned in #53, it would also be nice to be able to renew / replace Root and Issuer CA certificates.