* Add pki/root/sign-self-issued. This is useful for root CA rolling, and is also suitably dangerous. Along the way I noticed we weren't setting the authority key IDs anywhere, so I addressed that. * Add tests