Currently only contains `x5t` whish is sha-1. This should be changed to `x5t#S256` which uses SHA-2. This requirement should also be added to the RFC.