{security extensions] Implement the behavior associated to the AdditionalRootCertificateCheck configuration key : Only 1 Central System CA certificate at a time + 1 backup and new Central System CA must be signed by the old one.