Rated 3 out of 5 stars

Since SHA1 signatures are deprecated, a lot of certificates are re-issued pre-maturely by the CAs signed with SHA2 or SHA256. (e.g. ssllabs asks for this).
If the issuing organization is the same, and this change is visible, do not label the change yellow, but green!

regards cert-patrol-rh@p4u.ch

P.S.: BTW, do you have an issue-tracker?

This review is for a previous version of the add-on (2.0.14.1-signed.1-signed).