##### 7.1.3.2.3 DSA
The CA SHALL use the following signature algorithm:
* DSA with SHA-256
In addition, the CA MAY use `DSA with SHA-1` if one of the following conditions are met:
* It is used within Timestamp Authority Certificate and the date of the `notBefore` field is not greater than 2022-04-30; or,
* It is used within an OCSP response; or,
* It is used within a CRL; or,
* It is used within a Timestamp Token and the date of the `genTime` field is not greater than 2022-04-30.